Tag
#Account Takeover
Critical OAuth2/OIDC Account Takeover Vulnerability in AshAuthentication
A critical vulnerability (CVE-2026-49757, CVSS 9.2) in AshAuthentication's OAuth2 and OIDC strategies allows unauthenticated remote account takeover via email-based user matching. The vulnerability affects applications using AshAuthentication with OAuth2/OIDC configurations that do not strictly verify email ownership. An attacker can register an account with a victim's email on a vulnerable provider, then gain full local privileges through a standard OAuth flow.
Zero-Click Account Takeover via OAuth Identity Linking to Unverified Email Accounts
CVE-2026-35511 is an 8.7 severity vulnerability in Authorizer that allows for zero-click account takeover via OAuth identity linking to unverified email accounts. An attacker can pre-register with a victim's email address without verifying it and gain persistent password-based access to the victim's account after the victim completes a normal OAuth login.
CVE-2026-39923: Flarum Password Reset Token Expiry Bypass Vulnerability
A critical vulnerability (CVE-2026-39923, CVSS 8.1) in Flarum, a popular discussion platform, allows unauthenticated attackers to bypass the 24-hour password reset token expiry, potentially leading to unauthorized account takeovers. The vulnerability affects Flarum versions prior to 1.8.16. Organizations using Flarum should immediately upgrade to version 1.8.16 or later to mitigate this risk. Failure to do so may result in compromised user accounts and potential lateral movement within the network.
CVE-2026-9273: Critical Password Reset Link Poisoning Vulnerability in Kadence Memberships Plugin
A critical vulnerability (CVE-2026-9273, CVSS 9.3) exists in the Kadence Memberships plugin for WordPress, allowing unauthenticated attackers to poison password reset links, leading to account takeovers. The vulnerability affects all versions up to and including 4.0.0. Immediate patching is recommended to prevent potential account takeovers, especially for administrator accounts.
Auth.js Vulnerability: Homoglyph @ Bypass in Email Normalizer
A critical vulnerability in Auth.js allows an attacker to bypass email validation, potentially leading to account takeover. The flaw affects versions of `next-auth` and `@auth/core` when using the email/magic-link sign-in flow with the default identifier normalizer. Immediate action is required to prevent exploitation.
CVE-2026-35198: Critical Stored XSS Vulnerability in HeyForm
A critical stored cross-site scripting (XSS) vulnerability exists in HeyForm, an open-source form builder, prior to version 3.0.0-rc.7. A low-privileged team member can inject malicious JavaScript, leading to account takeover through privilege escalation when a team owner views the form. Update to version 3.0.0-rc.7 or later to mitigate.
Understanding and Defending Against CVE-2026-7655: Privilege Escalation in SureCart Plugin
CVE-2026-7655 is a privilege escalation vulnerability in the SureCart plugin for WordPress, allowing unauthenticated attackers to takeover accounts by manipulating user details via webhook events. This vulnerability has a CVSS score of 8.1 and affects versions up to 4.2.3 of the plugin. Understanding the root cause and attack vector is crucial for defenders to implement effective mitigations.
CVE-2026-11374: ManageEngine Products Vulnerable to Predictable SSO Ticket IDs Leading to Account Takeover
A critical vulnerability (CVE-2026-11374, CVSS score of 9) in multiple ManageEngine products allows unauthenticated users to predict SSO ticket IDs, leading to account takeover. Affected products include ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus. Immediate action is required to update vulnerable versions.