External risk intelligence

FriendsOfFlarum OAuth Discord Provider Allows Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-92161

The vulnerability affects an OAuth authentication provider integrated into a web application platform. Authentication portals and login services are public-facing by design to facilitate user access, making this service reachable and exposed to the internet in any standard deployment where external identity provider sign-in is enabled.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the FriendsOfFlarum OAuth integration, specifically with the Discord provider, could allow an unauthenticated attacker to impersonate users, including administrators, by exploiting how email verification is handled during sign-in. This issue arises when the Discord OAuth provider incorrectly trusts unverified email addresses, enabling an attacker to link their Discord account to an existing Flarum user's identity. While other providers were not confirmed to be vulnerable, the potential impact on user accounts warrants attention.

  • Attackers can impersonate users via Discord sign-in.
  • Compromised accounts could include administrators.
  • Confirm if Discord sign-in is enabled and assess exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by tricking the Flarum forum into accepting a Discord account with an unverified email address as legitimate. If the Discord OAuth provider is enabled, the attacker can sign up for Discord using a known Flarum user's email address, even if that email isn't verified by Discord. By then logging into Flarum using this Discord account, the attacker can impersonate the legitimate Flarum user, potentially gaining administrative access.

  • Attacker needs Discord account and victim's email.
  • Triggered by Discord sign-in flow.
  • Allows unauthorized account access.

Live Threat

Current exploitation, exposure, and threat context

The FriendsOfFlarum OAuth provider, when configured with Discord, could allow an unauthenticated attacker to impersonate existing users, including administrators. This occurs because the provider may not properly verify email addresses from Discord, enabling an attacker to link a Discord account with an unverified, but known, user email to that user's Flarum account. This could lead to unauthorized access and control over user accounts when Discord sign-in is enabled and the victim's email is not already linked to a Discord account.

  • User accounts and administrator privileges.
  • Linking attacker's Discord to victim's email.
  • Unauthorized access and account compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The FriendsOfFlarum OAuth provider, specifically its Discord integration, presents a critical risk for Flarum deployments. Given that OAuth services are typically internet-facing to enable external logins, application owners and platform teams should prioritize identifying all Flarum instances utilizing Discord OAuth. Confirming exposure and business criticality will inform the necessary triage and remediation planning.

  • Identify Flarum instances using Discord OAuth.
  • Verify Discord OAuth reachability and business impact.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the FriendsOfFlarum OAuth extension?

This software is an extension for the Flarum forum platform that adds support for external login methods. It allows users to authenticate using services like Facebook, GitHub, or Discord instead of creating a local password. By handling the handshake between these third-party identity providers and your forum, it enables convenient single sign-on functionality for community members.

How does CVE-2026-92161 break authentication?

The issue involves a failure to verify data integrity, classified as CWE-345. Specifically, the Discord integration fails to confirm that an email address returned by the provider is actually verified. By ignoring this check, the extension mistakenly treats unverified email addresses from Discord as trusted, allowing an attacker to bypass standard identity proofing.

Do I need a special setup to trigger this vulnerability?

Yes, the flaw requires the Discord OAuth provider to be enabled in your Flarum settings. An attacker must also know the email address of a target user that is not already associated with a Discord account. It is important to note that other providers bundled with the extension, such as GitHub or Facebook, are not affected by this specific logic error.

Is my Flarum forum at risk?

According to Halo Surface Signal, this vulnerability is highly relevant because authentication portals are designed to be public-facing to serve users. If your forum is accessible via the internet and has the Discord login feature turned on, an attacker can reach this endpoint to attempt account takeover. Private or internal instances are still vulnerable if they expose the login page to network traffic.

When should I update my FriendsOfFlarum OAuth extension?

You should prioritize updating immediately if your forum uses Discord for user authentication. The fix is included in versions 1.7.4 and 2.0.0-beta.4. Check your current extension version in the Flarum administration panel and apply these updates to ensure the software correctly validates email trust status before granting access.

References