OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63472

CRITICAL · CVSS 9.1 EPSS 0.59% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in Vendure allows an attacker to authenticate as a victim by exploiting the ExternalAuthenticationService, which does not require email ownership verification before binding an external identity to an existing account. This can lead to unauthorized access to sensitive customer information, including orders and personal data. Organizations using Vendure versions prior to 3.7.0, especially those with custom external authentication strategies, should prioritize updating to the latest version to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63472
Severity
CRITICAL
CVSS
9.1
EPSS
0.59%

Original NVD Description

Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing account. This can expose orders, addresses, and personal information and permit account changes or orders as the victim. Native-only email and password deployments and external strategies that always require provider-verified email ownership are unaffected, and new-account creation for an unused email remains permitted. This issue is fixed in version 3.7.0.