{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-92161/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:friendsofflarum:fof_oauth:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-92161"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fof/oauth (1.x \u003c 1.7.4, 2.0.0-beta.x \u003c 2.0.0-beta.4)"],"_cs_severities":["critical"],"_cs_tags":["web-application","authentication-bypass","cve-2026-92161"],"_cs_type":"advisory","_cs_vendors":["FriendsOfFlarum"],"content_html":"\u003cp\u003eThe FriendsOfFlarum \u003ccode\u003efof/oauth\u003c/code\u003e extension (CVE-2026-92161) contains a critical vulnerability that allows unauthenticated account takeover. When the Discord OAuth provider is enabled, the extension fails to verify the \u003ccode\u003everified\u003c/code\u003e flag returned by the Discord API. Discord may return an email address as unverified if the account's associated phone number has been validated, even if the email itself has not been confirmed.\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003efof/oauth\u003c/code\u003e extension incorrectly treats these unverified emails as trusted, passing them to the Flarum core \u003ccode\u003eprovideTrustedEmail()\u003c/code\u003e function. If the provided email address matches an existing user on the forum, Flarum automatically links the attacker-controlled Discord identity to that account and logs the attacker in as the victim. This enables complete account takeover, including administrative accounts, provided the attacker knows the victim's email address. The vulnerability affects version series 1.x before 1.7.4 and 2.0.0-beta versions before 2.0.0-beta.4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target Flarum forum that has the Discord OAuth provider enabled.\u003c/li\u003e\n\u003cli\u003eAttacker obtains the target victim's email address, which is associated with a Flarum account.\u003c/li\u003e\n\u003cli\u003eAttacker creates or configures a Discord account using the victim's email address as the primary account email.\u003c/li\u003e\n\u003cli\u003eAttacker verifies a phone number on the Discord account, which allows the email address to remain in an unverified state within the Discord ecosystem.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an OAuth authentication flow via the targeted Flarum forum using the compromised Discord account.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003efof/oauth\u003c/code\u003e extension receives the OAuth callback from Discord, including the victim's email address marked with \u003ccode\u003e\u0026quot;verified\u0026quot;: false\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe extension fails to validate the \u003ccode\u003e\u0026quot;verified\u0026quot;: false\u003c/code\u003e flag and calls \u003ccode\u003eprovideTrustedEmail()\u003c/code\u003e with the target's email.\u003c/li\u003e\n\u003cli\u003eFlarum core identifies the victim's account via the email address and completes the authentication, granting the attacker full access to the victim's session.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for complete account takeover, including administrative accounts, without requiring user interaction or knowledge of the user's password. Any forum utilizing the \u003ccode\u003efof/oauth\u003c/code\u003e extension with the Discord provider enabled is susceptible. The extent of the damage is dependent on the level of privilege held by the targeted accounts on the affected forums.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003efof/oauth\u003c/code\u003e extension to version 1.7.4 or 2.0.0-beta.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not feasible, disable the Discord OAuth provider in the Flarum extension settings to mitigate the risk of exploitation.\u003c/li\u003e\n\u003cli\u003eAudit user sessions and account linking logs for signs of suspicious OAuth association activity.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-25T20:06:25Z","date_published":"2026-09-25T20:06:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fof-oauth-takeover/","summary":"An unauthenticated account takeover vulnerability exists in the fof/oauth extension due to improper validation of unverified email addresses returned by the Discord OAuth provider, allowing attackers to hijack existing Flarum accounts.","title":"Unauthenticated Account Takeover in FriendsOfFlarum OAuth via Discord Provider","url":"https://feed.craftedsignal.io/briefs/2026-09-fof-oauth-takeover/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-92161","version":"https://jsonfeed.org/version/1.1"}