Nhost disclosed an improper authentication vulnerability, tracked as CVE-2026-41574 and GHSA-6G38-8J4P-J3PR, that allowed attackers to take over user accounts through flawed OAuth account-linking logic. In affected versions prior to 0.49.1, Nhost automatically linked an incoming OAuth identity to an existing local account when the email addresses matched, even if the third-party provider had not actually verified ownership of that email address.
The issue affected several OAuth adapters, including Discord, Bitbucket, AzureAD, and EntraID, where verification data could be mishandled or trusted incorrectly. An attacker could create a third-party identity using a victim’s email address without completing email verification, then sign in through OAuth and have Nhost merge that identity into the victim’s account, resulting in a fully authenticated session as the victim. Nhost patched the vulnerability in version 0.49.1.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Nhost released a fix for the account takeover issue in version 0.49.1. The vulnerability involved several adapters, including Discord, Bitbucket, AzureAD, and EntraID, that could incorrectly treat unverified email addresses as verified during OAuth login.
A severe improper authentication vulnerability affecting Nhost versions prior to 0.49.1 was publicly disclosed. The flaw allowed account takeover when OAuth identities were automatically linked to existing accounts based on matching email addresses even if the provider had not actually verified the email.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.