PT-2026-98894 · Flarum · Friendsofflarum Oauth
CVE-2026-92161
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FriendsOfFlarum OAuth versions prior to 1.7.4
FriendsOfFlarum OAuth versions prior to 2.0.0-beta.4
Description
An account takeover issue exists when the Discord OAuth provider is enabled. The provider fails to check the
verified field of the email address returned by Discord before passing it to the Flarum core via the provideTrustedEmail() function. Because Discord allows accounts to use unverified email addresses if a phone number is verified, an unauthenticated attacker who knows a user's email address can create a Discord account with that unverified address and a verified phone number. This allows the attacker to link their Discord identity to the victim's Flarum account and authenticate as the victim, including administrator accounts, without a password or victim interaction. This is possible only if the victim's email is not already linked to a Discord account.Recommendations
Update FriendsOfFlarum OAuth to version 1.7.4 or later.
Update FriendsOfFlarum OAuth to version 2.0.0-beta.4 or later.
As a temporary workaround, disable the Discord OAuth provider in the extension settings.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Friendsofflarum Oauth