Medium · 6.2 PHP packages GHSA-g7vj-c29h-3h5m CVE-2026-92161 PKSA-4zg4-dqk9-5wt7
Unauthenticated Account Takeover in FriendsOfFlarum OAuth via Discord Login (CVE-2026-92161)
A critical flaw in the fof/oauth package for Flarum lets an attacker take over any user account, including administrators, by abusing the Discord login provider's handling of unverified email addresses.
AI summary
A critical security issue has been disclosed in fof/oauth, the FriendsOfFlarum package that lets Flarum forum users log in via GitHub, Twitter, Facebook, Discord, and other third-party providers. The flaw specifically affects the Discord login integration and allows an unauthenticated attacker to take over existing user accounts, including administrator accounts, without needing a password or any interaction from the victim.
What happened
The fof/oauth package's Discord OAuth provider failed to check whether an email address returned by Discord was actually verified before passing it to Flarum core as a trusted email via the provideTrustedEmail() function. Because Discord allows an account to have an unverified email paired with a verified phone number, an attacker could register a Discord account using a victim's known email address without ever verifying it, and still have that email accepted as trusted by Flarum.
Technical cause
The root cause is classified as CWE-345, Insufficient Verification of Data Authenticity. The Discord provider in fof/oauth did not inspect the 'verified' field that Discord's API returns alongside the email address. Other bundled OAuth providers in the package were not confirmed to be practically exploitable this way, since their respective authentication flows only return email addresses that are already verified or confirmed.
Why it matters
By signing in with a Discord account configured with an unverified copy of a victim's email address, an attacker can cause Flarum to link that Discord identity to the victim's existing forum account. This grants the attacker authenticated access as the victim, with no password required and no action needed from the victim. The advisory notes this can be used to compromise administrator accounts, which could lead to full control over a Flarum forum.
Who is affected
Any Flarum installation that uses the fof/oauth package with the Discord sign-in provider enabled is potentially affected. Exploitation requires that the victim's email address is not already linked to a Discord account; if it is, the attack cannot be carried out against that account.
Affected versions
The vulnerability affects fof/oauth versions prior to 1.7.4, as well as the 2.0.0 beta line starting at 2.0.0-beta.1 up to (but not including) 2.0.0-beta.4.
Fixes and mitigation
The issue is fixed in fof/oauth versions 1.7.4 and 2.0.0-beta.4. Sites running an affected version should upgrade to one of these fixed releases.
Recommended action
Update fof/oauth to version 1.7.4 if running the 1.x line, or to 2.0.0-beta.4 if running the 2.0.0 beta line, as soon as possible. If an immediate update is not possible, consider disabling the Discord login provider until the upgrade is applied.
PatchBriefing score
6.2 / 10 · Medium
Official CVSS: 9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Why this score
This issue carries a CVSS base score of 9.8 (Critical), reflecting that it is exploitable over the network without authentication or any user interaction, and can fully compromise confidentiality, integrity, and availability of an affected account. The PatchBriefing score of 6.2 factors in the critical CVSS base score, the unauthenticated and no-interaction nature of the attack, and the fact that a fix is already available, while there is currently no evidence of known exploitation in the wild, public exploit code, or an EPSS-based likelihood estimate driving the score higher.
Affected versions
- fof/oauth >= 2.0.0-beta.1, < 2.0.0-beta.4
- vulnerable
- fof/oauth >=2.0.0-beta.1,<2.0.0-beta.4|<1.7.4
- vulnerable
- ≥ 1.7.4
- patched
- ≥ 2.0.0-beta.4
- patched
Reported fixes
The issue is fixed in fof/oauth versions 1.7.4 and 2.0.0-beta.4. Sites running an affected version should upgrade to one of these fixed releases.
How this was built
3 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email