PT-2026-94346 · Vendure · Vendure
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Vendure versions prior to 3.7.0
Description
An account takeover issue exists in the headless commerce platform where the
ExternalAuthenticationService.createCustomerAndUser() function links a new external authentication method to an existing user account based solely on an emailAddress match, without verifying if the email ownership was confirmed by the provider. In environments using a custom AuthenticationStrategy that forwards unverified emails, an attacker can use a victim's email address through an external provider to bind their own identity to the victim's account. This allows the attacker to access personal information, addresses, and orders, as well as modify account details or place orders on behalf of the victim. This issue specifically affects deployments using external or social authentication strategies that do not strictly require provider-verified email ownership.Recommendations
Upgrade to version 3.7.0.
As a temporary mitigation, restrict the use of custom
AuthenticationStrategy implementations that do not guarantee the verified status of the forwarded emailAddress.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vendure