External risk intelligence

Vendure Authentication Bypass Allows Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-63472

Vendure is a headless commerce platform designed to function as a public-facing web store or API. Since the vulnerability resides in the authentication and customer management services of this internet-facing application, the attack surface is commonly exposed to the public internet in standard deployment patterns.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Vendure headless commerce platform that could allow an attacker to impersonate a victim user. This issue impacts deployments using specific external authentication strategies where the email ownership has not been verified by the provider. Successful exploitation could expose sensitive customer data and enable unauthorized account changes or orders.

  • Attackers can impersonate users by bypassing email verification.
  • This affects customer data and account integrity in commerce platforms.
  • Confirming exposure in custom authentication setups is key.

Attack Path

How an attacker could exploit the issue

An attacker could potentially hijack existing customer accounts on a Vendure platform by exploiting a flaw in how it handles external authentication. If a deployment uses a custom authentication strategy that doesn't verify email ownership, an attacker could present a victim's email address to the system. The vulnerability allows the attacker to associate their own external identity with the victim's account, granting them access to sensitive information and the ability to impersonate the victim.

  • No authenticated access required.
  • Attacker binds external identity to victim account.
  • Exposes personal data and permits account takeover.

Live Threat

Current exploitation, exposure, and threat context

In deployments using a custom external authentication strategy that does not verify email ownership, an attacker could authenticate as a victim by using their email address. This would allow the attacker to bind their external identity to the victim's existing account, potentially exposing sensitive personal information, order history, and addresses, and enabling unauthorized account modifications or purchases. Native email/password authentication and external strategies that always verify email ownership are unaffected.

  • Customer account data
  • Unverified email forwarding
  • Account takeover and unauthorized actions

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Vendure deployments using custom external authentication strategies that do not verify email ownership. Application owners or platform teams responsible for the Vendure implementation should first identify all instances of the affected platform, determine their exposure and business criticality, and then coordinate with the vendor or internal teams for remediation.

  • Identify affected Vendure instances.
  • Verify reachability and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Vendure?

Vendure is an open-source, headless commerce platform used to build online stores and digital marketplaces. Unlike traditional all-in-one e-commerce tools, it provides a flexible API-first backend, allowing developers to create custom storefronts while managing products, orders, and customer accounts.

What is the vulnerability class for CVE-2026-63472?

This vulnerability is classified as CWE-287, which refers to Improper Authentication. In the context of Vendure, the system fails to adequately verify that a user actually owns the email address provided during external sign-in, allowing an attacker to link their own credentials to an existing victim's account.

How can an attacker trigger this issue?

An attacker exploits this by providing a victim's email address through a custom external authentication strategy that does not confirm the user owns that email. The system then incorrectly trusts the request and links the attacker's account to the victim's profile. Deployments using only native email and password logins, or external providers that strictly enforce verified email ownership, are not susceptible to this flaw.

Is my deployment at risk according to Halo Surface Signal?

Yes, if you use a custom external authentication strategy, your risk is likely high. Halo Surface Signal notes that because Vendure is typically deployed as a public-facing web store or API, it is designed to be accessible via the internet. If your authentication configuration fails to verify email ownership, the service is reachable and potentially vulnerable to unauthorized account access.

How do I address this CVE in my environment?

The primary step is to upgrade your Vendure instance to version 3.7.0 or later, which contains the necessary fix. Before updating, you should inventory your deployments to identify which use custom external authentication strategies and assess how those strategies handle email verification to prioritize your patching efforts.

References