{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vendure--3.7.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vendure:vendure:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-63472"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vendure (\u003c 3.7.0)"],"_cs_severities":["critical"],"_cs_tags":["account-takeover","authentication-bypass","web-application"],"_cs_type":"advisory","_cs_vendors":["Vendure"],"content_html":"\u003cp\u003eVendure versions prior to 3.7.0 contain a critical vulnerability in the \u003ccode\u003eExternalAuthenticationService\u003c/code\u003e that enables account takeover. The flaw exists in the \u003ccode\u003ecreateCustomerAndUser\u003c/code\u003e method, which links external OAuth or SSO authentication identities to existing customer accounts based solely on an email address match. Crucially, the system does not enforce that the provided email address is verified by the external identity provider.\u003c/p\u003e\n\u003cp\u003eIn deployments using custom \u003ccode\u003eAuthenticationStrategy\u003c/code\u003e implementations - specifically those that fail to validate the \u003ccode\u003eemail_verified\u003c/code\u003e claim or improperly handle unverified email addresses - an attacker can register an account on an external provider using a victim's email address. When this attacker authenticates against the vulnerable Vendure instance, the application incorrectly binds the attacker's external identity to the pre-existing account belonging to the victim. This results in the attacker gaining full access to the victim's account, including PII, order history, and the ability to perform unauthorized transactions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a Vendure instance configured with an external \u003ccode\u003eAuthenticationStrategy\u003c/code\u003e that does not enforce strict email verification.\u003c/li\u003e\n\u003cli\u003eAttacker creates an account on the external OIDC or OAuth provider using the target victim's email address (\u003ccode\u003evictim@example.com\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe external provider, not requiring rigorous verification, allows the registration.\u003c/li\u003e\n\u003cli\u003eAttacker initiates the authentication flow on the Vendure store using the external provider.\u003c/li\u003e\n\u003cli\u003eThe external provider passes the email address \u003ccode\u003evictim@example.com\u003c/code\u003e to the Vendure \u003ccode\u003eExternalAuthenticationService\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ecreateCustomerAndUser\u003c/code\u003e identifies a pre-existing user account associated with \u003ccode\u003evictim@example.com\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe system silently links the attacker's \u003ccode\u003eExternalAuthenticationMethod\u003c/code\u003e to the victim's account without checking the \u003ccode\u003everified\u003c/code\u003e status.\u003c/li\u003e\n\u003cli\u003eAttacker logs in using the linked external provider and gains full access to the victim's account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full account takeover, allowing attackers to read or modify victim PII, view private order histories, update shipping addresses, and place unauthorized orders on the victim's behalf. This vulnerability affects any Vendure deployment that utilizes external authentication strategies that accept unverified email claims.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Vendure instances to version 3.7.0 or later immediately to address CVE-2026-63472.\u003c/li\u003e\n\u003cli\u003eAudit all custom \u003ccode\u003eAuthenticationStrategy\u003c/code\u003e implementations to ensure they only set \u003ccode\u003everified: true\u003c/code\u003e when the external identity provider has explicitly verified the email address ownership.\u003c/li\u003e\n\u003cli\u003eImplement logic within custom \u003ccode\u003eAuthenticationStrategy\u003c/code\u003e code to prevent silent linking of unverified external identities to existing accounts; require active user authentication or session verification before linking new external providers.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-17T19:10:14Z","date_published":"2026-09-17T19:10:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vendure-auth-bypass/","summary":"Vendure is vulnerable to account takeover due to the ExternalAuthenticationService allowing unverified external identity linking to existing user accounts via email matching.","title":"Account Takeover Vulnerability in Vendure External Authentication","url":"https://feed.craftedsignal.io/briefs/2026-09-vendure-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Vendure (\u003c 3.7.0)","version":"https://jsonfeed.org/version/1.1"}