Skip to content
Threat Feed
high advisory

Duplicate Order Processing in Payload Ecommerce Stripe Adapter

A logic flaw in the @payloadcms/plugin-ecommerce Stripe payment adapter allows order confirmations to be processed multiple times, posing a risk of duplicate fulfillment.

CVE search metadata

CVE search record: CVE-2026-105850. KEV: no. Product: payloadcms/plugin-ecommerce (< 3.90.0, >= 4.0.0-canary.0 < 4.0.0-canary.34). Brief: Duplicate Order Processing in Payload Ecommerce Stripe Adapter. Brief link: https://feed.craftedsignal.io/briefs/2026-10-payload-ecommerce-race/

Payload CMS has disclosed a vulnerability in the @payloadcms/plugin-ecommerce package that impacts the handling of Stripe payment adapter events. Under specific conditions, an order confirmation can be processed more than once, potentially leading to duplicate transaction processing or redundant order fulfillment. This issue affects versions prior to 3.90.0 and certain 4.0.0-canary releases. This flaw is identified as CVE-2026-105850 and relates to the atomicity or idempotency of the confirmation processing logic within the plugin.

Impact

Successful exploitation of this logic flaw can result in financial discrepancies, unauthorized duplicate orders, and inventory or fulfillment errors for affected e-commerce deployments. The scope is limited to systems utilizing the @payloadcms/plugin-ecommerce with Stripe integration.

Recommendation

Prioritize the upgrade of the @payloadcms/plugin-ecommerce package to version 3.90.0 or higher, or 4.0.0-canary.34 or higher, to resolve CVE-2026-105850. In environments where immediate patching is not feasible, implement idempotency checks at the application or database layer to ensure Stripe webhooks related to order confirmation are only processed once per unique transaction identifier.

Mitigations

Upgrade @payloadcms/plugin-ecommerce to version 3.90.0 or 4.0.0-canary.34

immediate Development Team

CVE-2026-105850