← Back to search

CVE-2026-63472

9.1 CRITICALpublic exploit available

Published 2026-09-17 · Updated 2026-09-17

AI risk analysis

Summary
The flaw allows an attacker to authenticate with a victim's email and bind their external identity to the victim's account, exposing sensitive information and permitting account changes or orders as the victim.
Exploitability
Exploitation is relatively straightforward if the attacker can control the email being forwarded, as no verified ownership is required.
Blast radius
If exploited, this can lead to significant exposure of the victim's personal information and account control, impacting their orders and addresses.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 3.7.0 or later.
auth-bypassemailcommerce

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing account. This can expose orders, addresses, and personal information and permit account changes or orders as the victim. Native-only email and password deployments and external strategies that always require provider-verified email ownership are unaffected, and new-account creation for an unused email remains permitted. This issue is fixed in version 3.7.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-287

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.