Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-105850: CVE-2026-105850: Race Condition and Order Double-Processing in @payloadcms/plugin-ecommerce

CVE-2026-105850: Race Condition and Order Double-Processing in @payloadcms/plugin-ecommerce Vulnerability ID: CVE-2026-105850 CVSS Score: 8.8 Published: 2026-10-06 A high-severity race condition vulnerability exists

CVE-2026-105850: Race Condition and Order Double-Processing in @payloadcms/plugin-ecommerce

Vulnerability ID: CVE-2026-105850
CVSS Score: 8.8
Published: 2026-10-06

A high-severity race condition vulnerability exists in @payloadcms/plugin-ecommerce within the Stripe payment adapter's order confirmation pipeline. Unauthenticated attackers or parallel webhook deliveries can exploit sequential, non-atomic database operations to bypass state verifications, leading to duplicate order creation, multiple inventory decrements, and inconsistent database records.

TL;DR

Sequential, non-atomic database operations in @payloadcms/plugin-ecommerce allow concurrent requests to bypass state verification checks, leading to duplicate order creation and inventory depletion.

Technical Details

  • CWE ID: CWE-837
  • Attack Vector: Network (AV:N)
  • CVSS Score: 8.8 (High)
  • Impact: High Integrity, High Availability (Duplicate Orders & Inventory Depletion)
  • Exploit Status: None (No public exploits in the wild)
  • CISA KEV Status: Not Listed

Affected Systems

  • @payloadcms/plugin-ecommerce
  • payload
  • @payloadcms/plugin-ecommerce: < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: 6c0c4dc

Atomic transaction finalizer implementation to resolve order confirmation race conditions

Mitigation Strategies

  • Upgrade @payloadcms/plugin-ecommerce to version 3.90.0 or higher.
  • Generate and apply PostgreSQL database migrations to support the new transaction state.
  • Refactor custom payment adapters to use the centralized, atomic finalizeOrder callback.

Remediation Steps:

  1. Verify the current installed version of @payloadcms/plugin-ecommerce in your package.json.
  2. Execute your package manager's upgrade command to fetch version 3.90.0 or later (or 4.0.0-canary.34 or later for the 4.x branch).
  3. Generate database migrations locally by executing: npx payload migrate
  4. Deploy and run the generated migration on staging and production database environments.
  5. Review any internal custom billing or Stripe webhooks to verify compatibility with the new API signature.

References

Read the full report for CVE-2026-105850 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.