Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts (CVE-2026-35511)

0
High
Published: 08/14/2026 (08/14/2026, 15:36:15 UTC)
Source: GCVE Database
Product: github.com/authorizerdev/authorizer

Description

A vulnerability in Authorizer's OAuth callback handler allows an attacker to take over user accounts without user interaction by exploiting unverified email accounts. The system links OAuth identities to existing accounts matched by email without verifying the email was originally verified by the account owner. This flaw enables an attacker who pre-registers an account with a victim's email (unverified) to gain persistent password access after the victim logs in via OAuth. The attacker’s password remains valid and the victim is not notified of the linked OAuth identity.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Passive
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

Goghsa
github.com/authorizerdev/authorizer
Affected versions
<0.0.0-20260807033110-66fe488fd2a4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 16:38:54 UTC

Technical Analysis

The OAuth callback handler in Authorizer links incoming OAuth identities to existing user accounts by matching email addresses without verifying that the existing account's email was verified by its original owner. If an attacker pre-registers an account with a victim's email address but does not verify it, and the victim later logs in via OAuth, the system links the OAuth identity to the attacker's unverified account. The email is automatically marked as verified, the OAuth provider is appended to the signup methods, but the attacker's original password remains valid and is not invalidated or cleared. This allows the attacker persistent password-based access to the victim's account without any further interaction from the victim, constituting a zero-click account takeover. The vulnerability affects all OAuth providers configured in Authorizer. The root cause is a trust boundary violation where the system trusts the OAuth provider's email verification but incorrectly trusts the password set by the unverified attacker. The suggested fix is to verify that the existing account's email is verified before linking OAuth identities and to invalidate existing passwords or require re-authentication when linking new OAuth identities.

Potential Impact

This vulnerability allows full account takeover for any user who logs in via OAuth if an attacker has pre-registered an unverified account with the victim's email. The attacker maintains persistent password-based access even if the victim changes OAuth providers or revokes OAuth access. The victim has no indication that their account was pre-staged by the attacker. All data created by the victim after OAuth login is accessible to the attacker. The issue affects every OAuth provider configured in Authorizer, including Google, GitHub, Facebook, Apple, LinkedIn, Twitter, Discord, Twitch, Roblox, and Microsoft.

Mitigation Recommendations

A patch is available for this vulnerability. The vendor should be consulted for the official fix. The recommended remediation is to verify that the existing account's email is verified before linking an OAuth identity. If the email is not verified, the system should reject the login, create a new separate account, or delete the unverified account before creating a fresh one for the OAuth user. Additionally, when linking a new OAuth identity, any existing password on the account should be invalidated or the user should be required to re-authenticate via the original method. These steps prevent attackers from maintaining unauthorized password access after OAuth linking.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-29rf-f4vv-pvq6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-35511"]
Ecosystems
["Go"]
Database Specific Severity
HIGH
Cvss Version
4.0

Threat ID: 6a7f43e7bf8831d5395d5f0e

Added to database: 08/14/2026, 16:35:51 UTC

Last enriched: 08/14/2026, 16:38:54 UTC

Last updated: 08/14/2026, 22:31:57 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses