{"id":"CVE-2026-63472","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-63472","summary":"Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification","details":"# External-authentication account takeover: external login linked to a pre-existing account by email without requiring verification\n\n**Package:** @vendure/core (vendure-ecommerce/vendure, latest master) · \n\n> [!IMPORTANT]\n> This vulnerability **only affects deployments that use external / social authentication**\n(an `AuthenticationStrategy` other than the built-in native email/password strategy) where\nthat strategy can return an email address the external provider has **not verified** the\nuser owns.\n\n**You are affected if all of these are true:**\n- Your store configures one or more external `AuthenticationStrategy` implementations\n  (custom OAuth / social login / SSO), **and**\n- At least one forwards an `emailAddress` to `ExternalAuthenticationService` without\n  guaranteeing the provider verified ownership of it (e.g. it doesn't check the provider's\n  `email_verified` claim, or leaves `verified` unset/false), **and**\n- Customer accounts exist that share an email address with those external identities.\n\n**You are NOT affected if:**\n- You use only the built-in native (email/password) authentication with no external strategies, **or**\n- Every external strategy you use only ever returns provider-verified emails (and sets `verified: true`).\n\n**Remediation:** Upgrade to **3.7.0**. After upgrading, an external login is only linked to a\npre-existing account when the email is verified; a custom `AuthenticationStrategy` must set\n`verified: true` only for emails the provider has actually verified.\n\n## Summary\n`ExternalAuthenticationService.createCustomerAndUser()` links a newly-presented external (OAuth/social) authentication method to a **pre-existing User account selected purely by email-address match**, and it does so **without requiring `config.verified === true`**. If any configured `AuthenticationStrategy` forwards an email that was not proven to belong to the external identity (the classic `email_verified` omission — common with custom OAuth providers, or providers/strategies that don't validate email ownership), an attacker can register at that provider using a victim's email address, authenticate, and have their external identity bound to the victim's existing Vendure account — resulting in account takeover.\n\n## Vulnerable code\n`packages/core/src/service/helpers/external-authentication/external-authentication.service.ts` — `createCustomerAndUser`:\n```ts\nconst existingUser = await this.findExistingCustomerUserByEmailAddress(ctx, config.emailAddress);\nif (existingUser) {\n    user = existingUser;                 // <-- links to the EXISTING account, by email alone\n} else {\n    user = new User({ identifier: config.emailAddress, verified: config.verified || false, ... });\n}\nconst authMethod = await this.connection.getRepository(ctx, ExternalAuthenticationMethod).save(\n    new ExternalAuthenticationMethod({ externalIdentifier: config.externalIdentifier, strategy: config.strategy }),\n);\nuser.authenticationMethods = [...(user.authenticationMethods || []), authMethod];   // <-- external login attached\nawait this.connection.getRepository(ctx, User).save(user);\n```\n`config.verified` is used only to set `User.verified` and to write a `CUSTOMER_VERIFIED` history entry (later in the method) — it is **never** used to gate whether the external method may be attached to an existing account. So an unverified external email links to the victim's account just the same.\n\n## Impact\nAccount takeover of any customer whose email address an attacker can present (unverified) via an external auth provider — read/modify the victim's orders, addresses, and PII, and place orders as them. The blast radius depends on the deployed `AuthenticationStrategy`(ies): strategies that don't strictly require a provider-verified email (or providers that don't guarantee email ownership) are directly exploitable.\n\n## Reproduction (conceptual)\n1. Victim has a native Vendure customer account `victim@example.com`.\n2. Attacker authenticates through an external provider configured on the store, presenting `emailAddress = victim@example.com` with `verified` unset/false (depending on the strategy/provider).\n3. `createCustomerAndUser` finds the victim's existing User by email and attaches the attacker's `ExternalAuthenticationMethod`.\n4. Attacker logs in via that external method → authenticated as the victim.\n\n## Suggested fix\nRefuse to bind an external authentication method to a **pre-existing** account unless the email is provably verified, and prefer explicit, authenticated account-linking:\n```ts\nif (existingUser) {\n    if (!config.verified) {\n        // Do not silently link an unverified external identity to an existing account.\n        throw new EmailAddressConflictError(); // or require the user to link while logged in\n    }\n    user = existingUser;\n}\n```\nDocument clearly that an `AuthenticationStrategy` MUST only set `verified: true` for provider-verified emails, and that linking to existing accounts requires it.","published":"2026-09-17T14:50:22Z","modified":"2026-09-17T15:00:06.681857527Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@vendure/core","fixedVersion":"3.7.0"}],"fix":{"url":"https://github.com/vendurehq/vendure/commit/3bb04718ea4f9395fda731bd2a4bcfc3afb0a485","label":"vendurehq/vendure@3bb0471"},"references":[{"type":"WEB","url":"https://github.com/vendurehq/vendure/security/advisories/GHSA-6j36-r6pr-59x4"},{"type":"WEB","url":"https://github.com/vendurehq/vendure/commit/3bb04718ea4f9395fda731bd2a4bcfc3afb0a485"},{"type":"PACKAGE","url":"https://github.com/vendurehq/vendure"},{"type":"WEB","url":"https://github.com/vendurehq/vendure/releases/tag/v3.7.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T15:00:06.681857527Z"}}