{"id":"CVE-2026-63472","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-63472","generatedAt":"2026-09-20T12:35:56.248Z","title":"In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing…","description":"Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing account. This can expose orders, addresses, and personal information and permit account changes or orders as the victim. Native-only email and password deployments and external strategies that always require provider-verified email ownership are unaffected, and new-account creation for an unused email remains permitted. This issue is fixed in version 3.7.0.","published":"2026-09-17T15:16:50.000Z","lastModified":"2026-09-17T21:16:03.000Z","status":"Deferred","sourceIdentifier":"security-advisories@github.com","cvss":{"version":"3.1","score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"cwe":["CWE-287"],"affected":[],"epss":{"score":0.00411,"percentile":0.35093,"date":"2026-09-19","history":[]},"kev":{"listed":false},"exploits":{"count":0,"verified":false,"firstPublished":null,"source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[]},"verdict":{"level":"high","text":"High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit."},"changes":[],"references":[{"url":"https://github.com/vendurehq/vendure/commit/3bb04718ea4f9395fda731bd2a4bcfc3afb0a485","source":"security-advisories@github.com"},{"url":"https://github.com/vendurehq/vendure/releases/tag/v3.7.0","source":"security-advisories@github.com"},{"url":"https://github.com/vendurehq/vendure/security/advisories/GHSA-6j36-r6pr-59x4","source":"security-advisories@github.com"},{"url":"https://github.com/vendurehq/vendure/security/advisories/GHSA-6j36-r6pr-59x4","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63472","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}