{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apayload_cmspayloadcms_plugin_ecommerce/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload_cms:payloadcms_plugin_ecommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105850"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["payloadcms/plugin-ecommerce (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Payload CMS"],"content_html":"\u003cp\u003ePayload CMS has disclosed a vulnerability in the @payloadcms/plugin-ecommerce package that impacts the handling of Stripe payment adapter events. Under specific conditions, an order confirmation can be processed more than once, potentially leading to duplicate transaction processing or redundant order fulfillment. This issue affects versions prior to 3.90.0 and certain 4.0.0-canary releases. This flaw is identified as CVE-2026-105850 and relates to the atomicity or idempotency of the confirmation processing logic within the plugin.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this logic flaw can result in financial discrepancies, unauthorized duplicate orders, and inventory or fulfillment errors for affected e-commerce deployments. The scope is limited to systems utilizing the @payloadcms/plugin-ecommerce with Stripe integration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of the @payloadcms/plugin-ecommerce package to version 3.90.0 or higher, or 4.0.0-canary.34 or higher, to resolve CVE-2026-105850. In environments where immediate patching is not feasible, implement idempotency checks at the application or database layer to ensure Stripe webhooks related to order confirmation are only processed once per unique transaction identifier.\u003c/p\u003e\n","date_modified":"2026-10-06T18:47:45Z","date_published":"2026-10-06T18:47:45Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-ecommerce-race/","summary":"A logic flaw in the @payloadcms/plugin-ecommerce Stripe payment adapter allows order confirmations to be processed multiple times, posing a risk of duplicate fulfillment.","title":"Duplicate Order Processing in Payload Ecommerce Stripe Adapter","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-ecommerce-race/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:payload_cms:payloadcms_plugin_ecommerce:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}