PT-2026-29593 · Reviactyl · Reviactyl

Aymenelouadi

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-34456

CVSS v3.1

9.1

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Reviactyl versions 26.2.0-beta.1 through 26.2.0-beta.4
Description A flaw in the OAuth authentication process allowed for automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using a victim’s email address and gain full access to the victim's account without knowing their password, resulting in a full account takeover without prior authentication.
Recommendations Update to version 26.2.0-beta.5 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-34456

Affected Products

Reviactyl