CVE-2026-35511: Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account’s email was verified by its original owner. An attacker who pre-registers with a victim’s email address (without verifying it) gains persistent password-based access to the victim’s account after the victim completes a normal OAuth login. Verified against HEAD (commit 73679fa).
References
Code Behaviors & Features
Detect and mitigate CVE-2026-35511 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →