CRITICAL
9.1 CVE-2026-63472 Published 17 Sept 2026
Vendure Headless Commerce Platform Account Takeover Bug
Worried this affects your website?
Vendure, an open-source headless commerce platform, had a vulnerability in versions prior to 3.7.0.
ExternalAuthenticationService.createCustomerAndUser in the core service allowed an attacker to authenticate with a victim's email and bind the attacker's external identity to the victim's existing account, exposing personal information and permitting account changes or orders as the victim.
This issue is fixed in version 3.7.0.
Reference: CVE-2026-63472 on NVD
← Back to Security News