Zero-Click Account Takeover via OAuth Identity Linking to Unverified Email Accounts
CVE-2026-35511 is an 8.7 severity vulnerability in Authorizer that allows for zero-click account takeover via OAuth identity linking to unverified email accounts. An attacker can pre-register with a victim's email address without verifying it and gain persistent password-based access to the victim's account after the victim completes a normal OAuth login.