THREAT OPS › Threat News › [GHSA] GHSA-29rf-f4vv-pvq6 (high) — Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
[GHSA] GHSA-29rf-f4vv-pvq6 (high) — Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
GHSA-29rf-f4vv-pvq6 Severity: high CVE: CVE-2026-35511
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account's email was verified by its original owner. An attacker who pre-registers w
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-35511cve
- victim@company.comemail
Original source: https://github.com/advisories/GHSA-29rf-f4vv-pvq6