CVE-2026-63472
9.1 CRITICALpublic exploit availablePublished 2026-09-17 · Updated 2026-09-17
AI risk analysis
- Summary
- The flaw allows an attacker to authenticate with a victim's email and bind their external identity to the victim's account, exposing sensitive information and permitting account changes or orders as the victim.
- Exploitability
- Exploitation is relatively straightforward if the attacker can control the email being forwarded, as no verified ownership is required.
- Blast radius
- If exploited, this can lead to significant exposure of the victim's personal information and account control, impacting their orders and addresses.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 3.7.0 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing account. This can expose orders, addresses, and personal information and permit account changes or orders as the victim. Native-only email and password deployments and external strategies that always require provider-verified email ownership are unaffected, and new-account creation for an unused email remains permitted. This issue is fixed in version 3.7.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-287
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-94606PoC
- CRITICALCVE-2026-100741
- HIGHCVE-2026-100871PoC
- CRITICALCVE-2026-100886PoC
- CRITICALCVE-2026-101077PoC
- CRITICALCVE-2026-15210
- HIGHCVE-2026-15372
- HIGHCVE-2026-16036
Related by shared AI tags and CWE weakness class. Browse the full archive.