CVE-2026-92161

9.8

FriendsOfFlarum · oauth

The FriendsOfFlarum OAuth plugin fails to verify Discord email addresses, allowing unauthenticated attackers to hijack user accounts, including administrative accounts, via account linking.

Executive summary

A critical vulnerability in the FriendsOfFlarum OAuth plugin allows unauthenticated attackers to perform account takeovers by exploiting improper verification of Discord identity data.

Vulnerability

The Discord provider fails to validate the verified status of email addresses returned during the OAuth handshake. This flaw allows an unauthenticated attacker to bind a malicious Discord identity to a victim's account, resulting in full unauthorized access.

Business impact

The ability for an unauthenticated attacker to compromise arbitrary user accounts, including those with administrative privileges, poses a catastrophic risk to organizational security. Successful exploitation grants attackers full control over the compromised Flarum forum, leading to potential data exfiltration, service disruption, and total loss of account integrity. Given the 9.8 CVSS score, this vulnerability represents a critical threat requiring immediate remediation.

Remediation

Immediate Action: Update the FriendsOfFlarum oauth extension to version 1.7.4 or 2.0.0-beta.4 immediately.

Proactive Monitoring: Review forum authentication logs for irregular account linking activities or Discord-related sign-in spikes.

Compensating Controls: If the update cannot be applied immediately, disable the Discord OAuth provider within the Flarum administrative dashboard to neutralize the attack vector.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability is severe and provides a direct path to administrative account takeover without requiring victim interaction. Organizations utilizing the FriendsOfFlarum OAuth extension must prioritize applying the provided patches to versions 1.7.4 or 2.0.0-beta.4. If patching is not immediately feasible, the Discord integration should be disabled as a primary defensive measure to prevent unauthorized account access.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources