{"id":"CVE-2026-32700","aliases":["GHSA-57hq-95w6-v4fc"],"url":"https://o3.security/vulnerability/CVE-2026-32700","summary":"Devise has a confirmable \"change email\" race condition that permits user to confirm email they have no access to","details":"### Impact\n\nA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the `reconfirmable` option (the default when using Confirmable with email changes).\n\nBy sending two concurrent email change requests, an attacker can desynchronize the `confirmation_token` and `unconfirmed_email` fields. The confirmation token is sent to an email the attacker controls, but the `unconfirmed_email` in the database points to a victim's email address. When the attacker uses the token, the victim's email is confirmed on the attacker's account.\n\n### Patches\n\nThis is patched in Devise **v5.0.3**. Users should upgrade as soon as possible.\n\n### Workarounds\n\nApplications can override this specific method from Devise models to force `unconfirmed_email` to be persisted when unchanged: (assuming your model is `User`)\n\n```ruby\nclass User < ApplicationRecord\n  protected\n\n  def postpone_email_change_until_confirmation_and_regenerate_confirmation_token\n    unconfirmed_email_will_change!\n    super\n  end\nend\n```\n\nNote: Mongoid does not seem to respect that `will_change!` should force the attribute to be persisted, even if it did not really change, so you might have to implement a workaround similar to Devise by setting `changed_attributes[\"unconfirmed_email\"] = nil` as well.","published":"2026-03-18T20:55:55.034Z","modified":"2026-08-12T03:51:16.152570506Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"devise","fixedVersion":"5.0.3"}],"fix":{"url":"https://github.com/heartcombo/devise/pull/5784","label":"heartcombo/devise#5784"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32700.json"},{"type":"ADVISORY","url":"https://github.com/heartcombo/devise/security/advisories/GHSA-57hq-95w6-v4fc"},{"type":"ADVISORY","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/devise/GHSA-57hq-95w6-v4fc.yml"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32700"},{"type":"REPORT","url":"https://github.com/heartcombo/devise/issues/5783"},{"type":"FIX","url":"https://github.com/heartcombo/devise/pull/5784"},{"type":"PACKAGE","url":"https://github.com/heartcombo/devise"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/devise/CVE-2026-32700.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.152570506Z"}}