Listen to this Post
CVE-2026-105848 is a missing authorization vulnerability in the `@payloadcms/plugin-stripe` component of Payload CMS, a free and open-source headless content management system. The flaw is classified under CWE-749 (Exposed Dangerous Method or Function) and CWE-862 (Missing Authorization), and it affects the optional Stripe REST proxy feature provided by the plugin.
When the Stripe REST proxy is enabled, it creates an endpoint (/api/stripe/rest) that proxies requests to the Stripe API on the server side, using the configured Stripe secret key. This proxy is intended to be protected by Payload’s access control mechanisms, ensuring that only authorized users can invoke specific Stripe operations. However, due to insufficient access control enforcement, an authenticated user who can reach the proxy endpoint is able to execute Stripe operations that they should not be permitted to perform.
The vulnerability requires all of the following conditions to be true for an application to be affected: the application uses @payloadcms/plugin-stripe, the optional Stripe REST proxy is enabled, and an authenticated user can reach the proxy endpoint. Deployments that do not enable the Stripe REST proxy are not affected by this vulnerability. The CVSS v4.0 base score is 6.4, rated as Medium severity, with a network attack vector, low attack complexity, no user interaction required, and low privileges required. The impact includes subsequent high confidentiality and integrity impacts on the Stripe integration, though the vulnerability does not directly affect availability.
Affected versions include `@payloadcms/plugin-stripe` versions before 3.90.0, as well as canary versions from 4.0.0-canary.0 up to but not including 4.0.0-canary.34. The issue has been fixed in versions 3.90.0 and 4.0.0-canary.34. Users are advised to upgrade their Payload packages to these patched versions. If an immediate upgrade is not feasible, the recommended workaround is to disable the Stripe REST proxy entirely. If the proxy must remain enabled, access should be restricted to trusted users only, and the allowlist of permitted Stripe operations should be limited to only those that are absolutely required.
DailyCVE Form:
Platform: Payload CMS
Version: < 3.90.0
Vulnerability: Access Control
Severity: Moderate
date: 2026-10-06
Prediction: 2026-10-06
What Undercode Say
Install the plugin
pnpm add @payloadcms/plugin-stripe
Stripe plugin configuration with REST proxy enabled
stripeSecretKey: process.env.STRIPE_SECRET_KEY
rest: true Proxies Stripe REST API through Payload access control
Omit rest to disable the endpoint entirely
The vulnerable endpoint:
POST /api/stripe/rest
Recommended: use stripeProxy function server-side instead
stripeProxy({ method, path, body })
Exploit: (Educational Purposes!)
An authenticated user with access to the `/api/stripe/rest` endpoint can craft requests to perform Stripe operations that are not properly authorized by the Payload access control layer. For example, an authenticated user with low privileges could potentially invoke Stripe operations such as creating charges, issuing refunds, or modifying customer data through the proxy, depending on the allowlist configuration and the permissions granted to their account. The exploit requires only network access to the endpoint and valid authentication credentials; no user interaction is needed.
Protection: from this CVE
Upgrade `@payloadcms/plugin-stripe` to version 3.90.0 or later for stable releases, or to version 4.0.0-canary.34 or later for canary builds. If upgrading immediately is not possible, disable the Stripe REST proxy by omitting the `rest: true` configuration from the plugin setup. If the proxy must remain enabled, restrict access to trusted users only and configure the allowlist to include only the exact Stripe method names that are strictly required for your application’s functionality.
Impact:
An authenticated user could perform unintended Stripe operations through the optional Stripe REST proxy, leading to unauthorized actions within the Stripe integration and potential subsequent high impacts to confidentiality and integrity of Stripe-related data and transactions.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

