PT-2026-98894 · Flarum · Friendsofflarum Oauth

CVE-2026-92161

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FriendsOfFlarum OAuth versions prior to 1.7.4 FriendsOfFlarum OAuth versions prior to 2.0.0-beta.4
Description An account takeover issue exists when the Discord OAuth provider is enabled. The provider fails to check the verified field of the email address returned by Discord before passing it to the Flarum core via the provideTrustedEmail() function. Because Discord allows accounts to use unverified email addresses if a phone number is verified, an unauthenticated attacker who knows a user's email address can create a Discord account with that unverified address and a verified phone number. This allows the attacker to link their Discord identity to the victim's Flarum account and authenticate as the victim, including administrator accounts, without a password or victim interaction. This is possible only if the victim's email is not already linked to a Discord account.
Recommendations Update FriendsOfFlarum OAuth to version 1.7.4 or later. Update FriendsOfFlarum OAuth to version 2.0.0-beta.4 or later. As a temporary workaround, disable the Discord OAuth provider in the extension settings.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92161
GHSA-G7VJ-C29H-3H5M

Affected Products

Friendsofflarum Oauth