Security Flaw in Payload CMS's Stripe Plugin Exposes Users to Unintended Operations
CVE-2026-105848
6.4MEDIUM
What is CVE-2026-105848?
A vulnerability has been identified in the Payload CMS’s Stripe plugin, where an authenticated user with access to the activated optional Stripe REST proxy can perform actions that were unintended and unauthorized. This presents significant security risks, particularly for data integrity and financial transactions. It is crucial for users to update to the fixed versions 3.90.0 or 4.0.0-canary.34 to mitigate potential exploits.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
plugin-stripe < 3.90.0 < 3.90.0
