CVE-2026-63472: Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing account. This can expose orders, addresses, and personal information and permit account changes or orders as the victim. Native-only email and password deployments and external strategies that always require provider-verified email ownership are unaffected, and new-account creation for an unused email remains permitted. This issue is fixed in version 3.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vendureto a version that resolves this vulnerability.Fixed in 3.7.0
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use a custom external AuthenticationStrategy that can forward an email address without confirming that the external provider verified ownership of that address. Native-only email-and-password deployments and external strategies that always require provider-verified email ownership are unaffected.
What does an attacker need to exploit this issue?
The attacker needs to authenticate through an affected external authentication strategy while presenting the victim's email address without having verified ownership of it. If that email already belongs to an existing customer user, the attacker's external identity can be linked to that account.
Are accounts created with previously unused email addresses affected in the same way?
No. Creation of a new account for an unused email address remains permitted; the issue concerns linking an external authentication method to a pre-existing account selected by email address.
What should be done if upgrading is not immediately possible?
Ensure custom external AuthenticationStrategy implementations only forward email addresses whose ownership has been verified by the identity provider. This prevents unverified attacker-supplied email addresses from being used to link to existing accounts.
How can I identify potentially exposed users?
Review whether your custom external authentication strategy accepts or forwards unverified provider email addresses, and identify existing customer accounts using those external-login flows. The vulnerable behavior attaches a newly presented external authentication method to an existing user with the same email address.