PT-2026-94346 · Vendure · Vendure

·

CVE-2026-63472

·

Published

2026-09-17

·

Updated

2026-10-01

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vendure versions prior to 3.7.0
Description An account takeover issue exists in the headless commerce platform where the ExternalAuthenticationService.createCustomerAndUser() function links a new external authentication method to an existing user account based solely on an emailAddress match, without verifying if the email ownership was confirmed by the provider. In environments using a custom AuthenticationStrategy that forwards unverified emails, an attacker can use a victim's email address through an external provider to bind their own identity to the victim's account. This allows the attacker to access personal information, addresses, and orders, as well as modify account details or place orders on behalf of the victim. This issue specifically affects deployments using external or social authentication strategies that do not strictly require provider-verified email ownership.
Recommendations Upgrade to version 3.7.0. As a temporary mitigation, restrict the use of custom AuthenticationStrategy implementations that do not guarantee the verified status of the forwarded emailAddress.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63472
GHSA-6J36-R6PR-59X4

Affected Products

Vendure