CVE-2026-105850: CVE-2026-105850: Race Condition and Order Double-Processing in @payloadcms/plugin-ecommerce
CVE-2026-105850: Race Condition and Order Double-Processing in @payloadcms/plugin-ecommerce Vulnerability ID: CVE-2026-105850 CVSS Score: 8.8 Published: 2026-10-06 A high-severity race condition vulnerability exists
CVE-2026-105850: Race Condition and Order Double-Processing in @payloadcms/plugin-ecommerce
Vulnerability ID: CVE-2026-105850
CVSS Score: 8.8
Published: 2026-10-06
A high-severity race condition vulnerability exists in @payloadcms/plugin-ecommerce within the Stripe payment adapter's order confirmation pipeline. Unauthenticated attackers or parallel webhook deliveries can exploit sequential, non-atomic database operations to bypass state verifications, leading to duplicate order creation, multiple inventory decrements, and inconsistent database records.
TL;DR
Sequential, non-atomic database operations in @payloadcms/plugin-ecommerce allow concurrent requests to bypass state verification checks, leading to duplicate order creation and inventory depletion.
Technical Details
- CWE ID: CWE-837
- Attack Vector: Network (AV:N)
- CVSS Score: 8.8 (High)
- Impact: High Integrity, High Availability (Duplicate Orders & Inventory Depletion)
- Exploit Status: None (No public exploits in the wild)
- CISA KEV Status: Not Listed
Affected Systems
- @payloadcms/plugin-ecommerce
- payload
-
@payloadcms/plugin-ecommerce: < 3.90.0 (Fixed in:
3.90.0) -
payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: 6c0c4dc
Atomic transaction finalizer implementation to resolve order confirmation race conditions
Mitigation Strategies
- Upgrade @payloadcms/plugin-ecommerce to version 3.90.0 or higher.
- Generate and apply PostgreSQL database migrations to support the new transaction state.
- Refactor custom payment adapters to use the centralized, atomic finalizeOrder callback.
Remediation Steps:
- Verify the current installed version of @payloadcms/plugin-ecommerce in your package.json.
- Execute your package manager's upgrade command to fetch version 3.90.0 or later (or 4.0.0-canary.34 or later for the 4.x branch).
- Generate database migrations locally by executing: npx payload migrate
- Deploy and run the generated migration on staging and production database environments.
- Review any internal custom billing or Stripe webhooks to verify compatibility with the new API signature.
References
Read the full report for CVE-2026-105850 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.