CRITICAL
FriendsOfFlarum
CVE published 2026-09-25
CVE-2026-92161
CVE-2026-92161 is a critical vulnerability in the FriendsOfFlarum OAuth plugin for Flarum, allowing unauthenticated attackers to link their Discord identity to an existing user's account and authenticate as the victim without a password or interaction. This issue arises from the plugin's failure to verify the email address returned by the Discord OAuth provider before passing it to Flarum core as trusted. [truncated]