Description
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing account. This can expose orders, addresses, and personal information and permit account changes or orders as the victim. Native-only email and password deployments and external strategies that always require provider-verified email ownership are unaffected, and new-account creation for an unused email remains permitted. This issue is fixed in version 3.7.0.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via external authentication linkage
Action: Patch now
AI Analysis

Impact

A flaw in Vendure’s external authentication service allows an attacker to bind an external login to an existing user account without verifying the email address. By supplying a victim’s email address through a custom authentication strategy that does not enforce provider‑verified ownership, the attacker’s external identity becomes linked to the victim’s account. The attacker can then view orders, addresses, and personal information, and may place orders or make account changes as the victim.

Affected Systems

VendureHQ’s Vendure headless commerce platform, all versions published before 3.7.0. Systems using the external authentication service with custom strategies that accept unverified emails are affected. Native‑only email/password deployments and strategies that enforce provider‑verified email are not impacted. New‑account creation for unused emails remains permitted.

Risk and Exploitability

The CVSS score of 9.1 indicates a high‑severity vulnerability. The EPSS score is not available, so the current exploitation likelihood is unclear; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an external authentication provider that forwards an unverified email address. An attacker exploiting this flaw can bind their external identity to a victim’s account without any additional information, thereby achieving unauthorized access and potential financial fraud.

Generated by OpenCVE AI on September 17, 2026 at 20:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply patch version 3.7.0 or newer to the Vendure deployment.
  • Configure or replace any custom external authentication strategy so that it requires provider‑verified email addresses before binding to a customer account.
  • If upgrading is not immediately feasible, disable external authentication for accounts that rely on unverified emails or enforce server‑side checks that reject external bindings to existing accounts when the email has not been verified.

Generated by OpenCVE AI on September 17, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6j36-r6pr-59x4 Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
History

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vendure
Vendure vendure
Vendors & Products Vendure
Vendure vendure

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing account. This can expose orders, addresses, and personal information and permit account changes or orders as the victim. Native-only email and password deployments and external strategies that always require provider-verified email ownership are unaffected, and new-account creation for an unused email remains permitted. This issue is fixed in version 3.7.0.
Title Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:21:11.192Z

Reserved: 2026-07-16T21:37:45.769Z

Link: CVE-2026-63472

cve-icon Vulnrichment

Updated: 2026-09-17T15:21:03.123Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:16:49.743

Modified: 2026-09-17T21:16:02.560

Link: CVE-2026-63472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses