CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105848

CVE-2026-105848: Insufficient Access Control in Payload CMS Stripe REST Proxy

Alon Barad
Alon Barad
Software Engineer

Oct 7, 2026·7 min read·6 visits

Executive Summary (TL;DR)

The Payload CMS Stripe plugin REST proxy failed to validate user roles or restrict executable SDK methods. This allowed any standard authenticated user to issue refunds, alter billing models, or exfiltrate customer metadata using the server's master Stripe Secret Key.

An access control vulnerability in `@payloadcms/plugin-stripe` allows authenticated low-privilege users to bypass authorization boundaries and execute arbitrary, highly privileged operations on the connected Stripe platform via an exposed REST proxy.

Vulnerability Overview

The @payloadcms/plugin-stripe npm package provides integration capabilities between Payload CMS and the Stripe payment platform. When developers enable the optional REST API proxy via the plugin configuration, an endpoint is automatically exposed at /api/stripe/rest to handle incoming payment management queries from frontend components.

A critical design flaw exists in @payloadcms/plugin-stripe versions prior to 3.90.0 and 4.0.0-canary.34 where the REST proxy endpoint does not implement sufficient access control. Any authenticated user, regardless of their role or administrative privileges, can reach this endpoint and interact directly with the Stripe SDK. Because the backend server acts as a proxy, all requests are executed under the authority of the server's master Stripe API Secret Key.

This exposure allows standard authenticated users to execute highly privileged administrative operations directly on the connected Stripe account, bypassing the CMS admin interface. The vulnerability has been assigned CVE-2026-105848 and carries a CVSS v4.0 score of 6.4, indicating moderate-to-high severity. Organizations utilizing this plugin in multi-user environments with the proxy enabled face significant operational risk.

Root Cause Analysis

The underlying security issues can be classified under CWE-749 (Exposed Dangerous Method or Function) and CWE-862 (Missing Authorization). When configuring the Stripe plugin with the legacy property rest: true, the application automatically registers a POST route handler named stripeREST in the file packages/plugin-stripe/src/routes/rest.ts. This handler processes incoming client-side payloads and forwards them directly to the Stripe service.

The primary authorization check in vulnerable versions only verifies the existence of a standard user session object in the incoming request. If the user is authenticated in any capacity, the application proceeds to parse the request body. No further role-based access control (RBAC) or attribute-based access control (ABAC) checks are performed to ensure the caller has administrative rights.

Furthermore, the route handler extracts the parameters stripeMethod and stripeArgs directly from the user-controlled POST request body without sanitization. These parameters are passed directly to the stripeProxy() utility function, which invokes the corresponding method on the master Stripe SDK instance. Because the application does not validate the requested method against an allowlist, any valid Stripe SDK method can be invoked dynamically.

Code and Patch Analysis

To understand the precise vulnerability mechanics, we must examine the difference between the legacy route handler and the patched version implemented in commit 2f94a4205e5ba3ec0e91c92ed54f24f429826dd0. In the vulnerable implementation, the endpoint immediately processed dynamic parameters once basic authentication was confirmed.

The patched implementation addresses both authentication and authorization by introducing a strict allowlist and a custom access callback. The route handler now checks if pluginConfig.rest is configured as a configuration object rather than a boolean value. If it is disabled or is not configured with exact properties, the handler rejects the query immediately with an error.

Below is the refactored code structure implemented in packages/plugin-stripe/src/routes/rest.ts that enforces authorization boundaries and method limits:

// Checking authorization using custom callback or defaulting to admin access
let hasAccess: boolean
if (pluginConfig.rest.access) {
  try {
    hasAccess = await pluginConfig.rest.access({ req })
  } catch (err) {
    return unexpectedErrorResponse({ err, req })
  }
} else {
  try {
    hasAccess = await hasAdminAccess({ req })
  } catch (err) {
    return unexpectedErrorResponse({ err, req })
  }
}
 
if (!hasAccess) {
  return errorResponse({ message: 'Forbidden', status: 403 })
}
 
const { stripeArgs, stripeMethod } = req.data ?? {}
 
// Enforcing strict allowlist validation
if (!pluginConfig.rest.allowedMethods.includes(stripeMethod)) {
  return errorResponse({ message: 'Invalid request', status: 400 })
}

Additionally, the configuration sanitizer in sanitizeStripeRESTConfig.ts prevents wildcard definitions or loose inputs during initialization. If a developer attempts to use rest: true, the configuration sanitizer throws a migration error. It mandates a non-empty allowedMethods array containing exact, literal method names, and rejects any configuration that attempts to use the wildcard character.

Attack Methodology & Exploitation

Exploitation of CVE-2026-105848 requires standard, low-privilege authentication on the target Payload CMS instance. The attacker must possess credentials or an active JWT session token associated with a basic CMS account. This requirement represents a low barrier to entry, particularly in applications that allow public registration or host standard user-facing features.

The attacker interacts with the target system by sending a crafted HTTP POST request to the /api/stripe/rest endpoint. The request includes the standard authentication headers and a JSON payload specifying the target Stripe method. To perform unauthorized operations, the attacker populates stripeMethod with highly privileged actions, such as refunds.create or subscriptions.del.

An example of an HTTP request designed to issue an unauthorized refund is shown below:

POST /api/stripe/rest HTTP/1.1
Host: target-payload-cms.com
Content-Type: application/json
Authorization: JWT <standard_user_session_token>
 
{
  "stripeMethod": "refunds.create",
  "stripeArgs": [
    {
      "charge": "ch_3MvY2lKxyz..."
    }
  ]
}

The exploitation flow is represented in the diagram below:

Upon receiving this payload, the backend application verifies that the user session is active. It then bypasses any further validation and forwards the arguments to the Stripe SDK. The SDK uses the server's legitimate master credentials to authenticate with Stripe's cloud API, which successfully processes the refund and returns the structured transaction response to the attacker.

Impact Assessment

The impact of this vulnerability is substantial and directly threatens the financial and operational integrity of organizations using the affected plugin. Because the Stripe REST proxy runs with the server's master API Secret Key, any successful exploitation grants the attacker equivalent administrative power over the connected Stripe account. This level of exposure bypasses all administrative dashboards and payment verification controls.

Attackers can exploit this access to execute disruptive actions, such as issuing massive unauthorized refunds to deplete store balances. They can also delete active customer subscription models, modify billing tiers, or retrieve sensitive customer lists and transactional history. This potential for unauthorized data exfiltration raises severe compliance and privacy concerns under regulations like GDPR and PCI-DSS.

While the vulnerability itself does not lead directly to remote code execution on the local host, the downstream impact on backend business systems is severe. This is reflected in the CVSS v4.0 metrics where subsequent confidentiality and integrity impacts are rated as High (SC:H/SI:H). The attack complexity is low, and no user interaction is required from the victims, making automated exploitation highly feasible once an attacker gains basic access.

Remediation & Hardening

Remediation of CVE-2026-105848 requires updating the @payloadcms/plugin-stripe dependency to a secure version. For the 3.x release line, organizations must upgrade to version 3.90.0 or higher. For deployments using the 4.x canary branch, the package must be upgraded to version 4.0.0-canary.34 or higher. These updates remove support for the vulnerable boolean configuration.

After upgrading the library, administrators must refactor their configuration files to replace any instance of rest: true. The secure configuration model requires defining an object that specifies exactly which Stripe methods are permitted. This is accomplished by populating the allowedMethods array and implementing an access callback to restrict execution to administrative roles.

A secure configuration structure is illustrated in the following TypeScript example:

stripePlugin({
  stripeSecretKey: process.env.STRIPE_SECRET_KEY,
  rest: {
    allowedMethods: ['subscriptions.list', 'customers.retrieve'],
    access: async ({ req }) => {
      // Ensure the user has the 'admin' role
      return Boolean(req.user && req.user.roles?.includes('admin'));
    }
  }
})

In environments where immediate patching is not possible, organizations must disable the REST proxy entirely. This is done by setting rest: false or removing the rest property from the plugin configuration, which defaults to undefined (disabled). Furthermore, security teams should audit their Stripe API logs for unusual endpoint invocations originating from backend servers to detect potential prior exploitation.

Official Patches

Payload CMSGitHub Security Advisory GHSA-r9v2-gg2j-22q5
Payload CMSSecurity Patch Commit
Payload CMSOfficial Release Version 3.90.0

Fix Analysis (1)

Technical Appendix

CVSS Score
6.4/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

Affected Systems

@payloadcms/plugin-stripe

Affected Versions Detail

Product
Affected Versions
Fixed Version
@payloadcms/plugin-stripe
Payload CMS
< 3.90.03.90.0
@payloadcms/plugin-stripe (canary)
Payload CMS
< 4.0.0-canary.344.0.0-canary.34
AttributeDetail
CWE IDCWE-749, CWE-862
Attack VectorNetwork (AV:N)
CVSS v4.0 Score6.4 (Medium)
Exploit StatusProof-of-Concept / Easy to reproduce
CISA KEV StatusNot Listed
Vulnerability TypeMissing Authorization in Stripe REST Proxy

MITRE ATT&CK Mapping

T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-749
Exposed Dangerous Method or Function

The product exposes a dangerous method or function to unauthorized or lower-privileged users, or fails to perform authorization checks altogether.

References & Sources

  • [1]Payload CMS Stripe REST Proxy Authorization Bypass Security Advisory
  • [2]GitHub Security Commit 2f94a42
  • [3]Payload Release Notes v3.90.0

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•33 minutes ago•CVE-2026-105845
9.8

CVE-2026-105845: SQL Injection and Access Control Bypass in Payload CMS Adapters via Case-Sensitivity Flaws and Sorting

A critical SQL Injection and access control bypass vulnerability was identified in Payload CMS database adapters (SQLite and PostgreSQL using Drizzle ORM internally). The vulnerability arises from case-sensitive logical operator checks during path validation and unvalidated sort queries. This allows remote attackers to bypass access control rules, execute unauthorized queries, and retrieve sensitive data through blind SQL injection side channels.

Alon Barad
Alon Barad
2 views•7 min read
•about 2 hours ago•CVE-2026-105844
9.3

CVE-2026-105844: Remote Code Execution via Prototype Pollution in @payloadcms/plugin-import-export

A critical prototype pollution vulnerability in the import-export plugin of Payload CMS allows unauthenticated remote attackers to bypass access controls and achieve remote code execution.

Alon Barad
Alon Barad
2 views•6 min read
•about 3 hours ago•CVE-2026-105806
8.6

CVE-2026-105806: Privilege Escalation and Missing Authorization in @payloadcms/plugin-mcp

CVE-2026-105806 is an improper access control vulnerability within the Model Context Protocol (MCP) plugin for Payload CMS. Authenticated users with low privileges can manipulate API key creation and mapping to associate keys with arbitrary users, including administrators. This allows total session takeovers and privilege escalation via MCP-authenticated API requests.

Alon Barad
Alon Barad
6 views•5 min read
•about 5 hours ago•CVE-2026-105851
9.3

CVE-2026-105851: Privilege Escalation via Field Access Control Bypass in Payload CMS Duplication Mechanism

A critical access control bypass vulnerability (CVE-2026-105851) in Payload CMS allows authenticated users to bypass field-level access controls during document duplication. By duplicating high-privilege documents, such as administrator accounts, standard users can inherit sensitive fields (e.g., role configurations or API keys), leading to privilege escalation.

Alon Barad
Alon Barad
6 views•7 min read
•about 6 hours ago•CVE-2026-105853
7.1

CVE-2026-105853: Sensitive Information Disclosure and Authentication Collection Boundary Bypass in Payload CMS

CVE-2026-105853 is a high-severity information disclosure vulnerability in Payload CMS that affects authentication-enabled collections. In vulnerable versions, the application fails to properly serialize and sanitize user documents during token refresh and password reset operations. This deficiency leaks hidden and read-restricted fields to unauthorized actors. Additionally, a logical flaw in token refresh validation allows low-privileged users to cross collection boundaries, exposing sensitive configuration details and administrative metadata.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 7 hours ago•CVE-2026-105852
5.3

CVE-2026-105852: Authorization Bypass and Related-Document Oracle in Payload CMS

An authorization bypass vulnerability in Payload CMS enables unauthenticated attackers to query and infer the existence of restricted documents via nested relationship queries on public collections. This cross-document contamination flaw affects both MongoDB and Drizzle SQL database adapters, allowing unauthorized reads of relationship metadata.

Amit Schendel
Amit Schendel
5 views•6 min read