CVE-2026-105848: Insufficient Access Control in Payload CMS Stripe REST Proxy
Vulnerability ID: CVE-2026-105848
CVSS Score: 6.4
Published: 2026-10-06
An access control vulnerability in @payloadcms/plugin-stripe allows authenticated low-privilege users to bypass authorization boundaries and execute arbitrary, highly privileged operations on the connected Stripe platform via an exposed REST proxy.
TL;DR
The Payload CMS Stripe plugin REST proxy failed to validate user roles or restrict executable SDK methods. This allowed any standard authenticated user to issue refunds, alter billing models, or exfiltrate customer metadata using the server's master Stripe Secret Key.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-749, CWE-862
- Attack Vector: Network (AV:N)
- CVSS v4.0 Score: 6.4 (Medium)
- Exploit Status: Proof-of-Concept / Easy to reproduce
- CISA KEV Status: Not Listed
- Vulnerability Type: Missing Authorization in Stripe REST Proxy
Affected Systems
- @payloadcms/plugin-stripe
-
@payloadcms/plugin-stripe: < 3.90.0 (Fixed in:
3.90.0) -
@payloadcms/plugin-stripe (canary): < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: 2f94a42
Implement strict validation and access controls in the Stripe plugin REST handler. Deprecate boolean configuration in favor of explicit allowedMethods and custom access controls.
Mitigation Strategies
- Upgrade @payloadcms/plugin-stripe to version 3.90.0 or higher.
- Upgrade to version 4.0.0-canary.34 or higher if utilizing the 4.x canary branch.
- Refactor plugin configurations to replace boolean 'rest: true' flags with structured objects enforcing explicit method allowlists and custom RBAC functions.
- Disable the REST proxy entirely if client-side Stripe integrations are not strictly required.
Remediation Steps:
- Identify deployments utilizing @payloadcms/plugin-stripe in the codebase.
- Check package.json to verify if the active version is below 3.90.0 or below 4.0.0-canary.34.
- Run 'npm install @payloadcms/plugin-stripe@latest' or 'yarn upgrade' to fetch the secure versions.
- Open the Payload CMS configuration file (typically payload.config.ts).
- Locate the stripePlugin() initialization block.
- If 'rest: true' is configured, modify it to use the new object format containing 'allowedMethods' and an explicit administrative 'access' callback.
- Verify the deployment by sending a test POST request with an unlisted method to confirm a 400 or 403 response is returned.
References
- Payload CMS Stripe REST Proxy Authorization Bypass Security Advisory
- GitHub Security Commit 2f94a42
- Payload Release Notes v3.90.0
Read the full report for CVE-2026-105848 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)