Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts (CVE-2026-35511)
A vulnerability in Authorizer's OAuth callback handler allows an attacker to take over user accounts without user interaction by exploiting unverified email accounts. The system links OAuth identities to existing accounts matched by email without verifying the email was originally verified by the account owner. This flaw enables an attacker who pre-registers an account with a victim's email (unverified) to gain persistent password access after the victim logs in via OAuth. The attacker’s password remains valid and the victim is not notified of the linked OAuth identity.
AI Analysis
Technical Summary
The OAuth callback handler in Authorizer links incoming OAuth identities to existing user accounts by matching email addresses without verifying that the existing account's email was verified by its original owner. If an attacker pre-registers an account with a victim's email address but does not verify it, and the victim later logs in via OAuth, the system links the OAuth identity to the attacker's unverified account. The email is automatically marked as verified, the OAuth provider is appended to the signup methods, but the attacker's original password remains valid and is not invalidated or cleared. This allows the attacker persistent password-based access to the victim's account without any further interaction from the victim, constituting a zero-click account takeover. The vulnerability affects all OAuth providers configured in Authorizer. The root cause is a trust boundary violation where the system trusts the OAuth provider's email verification but incorrectly trusts the password set by the unverified attacker. The suggested fix is to verify that the existing account's email is verified before linking OAuth identities and to invalidate existing passwords or require re-authentication when linking new OAuth identities.
Potential Impact
This vulnerability allows full account takeover for any user who logs in via OAuth if an attacker has pre-registered an unverified account with the victim's email. The attacker maintains persistent password-based access even if the victim changes OAuth providers or revokes OAuth access. The victim has no indication that their account was pre-staged by the attacker. All data created by the victim after OAuth login is accessible to the attacker. The issue affects every OAuth provider configured in Authorizer, including Google, GitHub, Facebook, Apple, LinkedIn, Twitter, Discord, Twitch, Roblox, and Microsoft.
Mitigation Recommendations
A patch is available for this vulnerability. The vendor should be consulted for the official fix. The recommended remediation is to verify that the existing account's email is verified before linking an OAuth identity. If the email is not verified, the system should reject the login, create a new separate account, or delete the unverified account before creating a fresh one for the OAuth user. Additionally, when linking a new OAuth identity, any existing password on the account should be invalidated or the user should be required to re-authenticate via the original method. These steps prevent attackers from maintaining unauthorized password access after OAuth linking.
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts (CVE-2026-35511)
Description
A vulnerability in Authorizer's OAuth callback handler allows an attacker to take over user accounts without user interaction by exploiting unverified email accounts. The system links OAuth identities to existing accounts matched by email without verifying the email was originally verified by the account owner. This flaw enables an attacker who pre-registers an account with a victim's email (unverified) to gain persistent password access after the victim logs in via OAuth. The attacker’s password remains valid and the victim is not notified of the linked OAuth identity.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OAuth callback handler in Authorizer links incoming OAuth identities to existing user accounts by matching email addresses without verifying that the existing account's email was verified by its original owner. If an attacker pre-registers an account with a victim's email address but does not verify it, and the victim later logs in via OAuth, the system links the OAuth identity to the attacker's unverified account. The email is automatically marked as verified, the OAuth provider is appended to the signup methods, but the attacker's original password remains valid and is not invalidated or cleared. This allows the attacker persistent password-based access to the victim's account without any further interaction from the victim, constituting a zero-click account takeover. The vulnerability affects all OAuth providers configured in Authorizer. The root cause is a trust boundary violation where the system trusts the OAuth provider's email verification but incorrectly trusts the password set by the unverified attacker. The suggested fix is to verify that the existing account's email is verified before linking OAuth identities and to invalidate existing passwords or require re-authentication when linking new OAuth identities.
Potential Impact
This vulnerability allows full account takeover for any user who logs in via OAuth if an attacker has pre-registered an unverified account with the victim's email. The attacker maintains persistent password-based access even if the victim changes OAuth providers or revokes OAuth access. The victim has no indication that their account was pre-staged by the attacker. All data created by the victim after OAuth login is accessible to the attacker. The issue affects every OAuth provider configured in Authorizer, including Google, GitHub, Facebook, Apple, LinkedIn, Twitter, Discord, Twitch, Roblox, and Microsoft.
Mitigation Recommendations
A patch is available for this vulnerability. The vendor should be consulted for the official fix. The recommended remediation is to verify that the existing account's email is verified before linking an OAuth identity. If the email is not verified, the system should reject the login, create a new separate account, or delete the unverified account before creating a fresh one for the OAuth user. Additionally, when linking a new OAuth identity, any existing password on the account should be invalidated or the user should be required to re-authenticate via the original method. These steps prevent attackers from maintaining unauthorized password access after OAuth linking.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-29rf-f4vv-pvq6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-35511"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a7f43e7bf8831d5395d5f0e
Added to database: 08/14/2026, 16:35:51 UTC
Last enriched: 08/14/2026, 16:38:54 UTC
Last updated: 08/14/2026, 22:31:57 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.