OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-105850: Payload Ecommerce has an order confirmation validation issue

GitHub Advisories · officialPublished Oct 6, 2026Risk 37/100

## Impact When using the Stripe payment adapter, an order confirmation could be processed more than once under certain conditions. You are affected if: - You use `@payloadcms/plugin-ecommerce` with the Stripe payment adapter. Deployments that do not use the Stripe payment flow are not affected. ## Patches Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. ## Workarounds Ensure Stripe order confirmations can only be processed once. This is a temporary mitigation; upgrading to a patched version is recommended.

Upgrade affected packages to a patched version: @payloadcms/plugin-ecommerce 3.90.0, @payloadcms/plugin-ecommerce 4.0.0-canary.34.

Vendor
Not specified
Product
@payloadcms/plugin-ecommerce
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source