Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-34456

Reviactyl: OAuth account takeover via auto-linking
Back to all
CVE

CVE-2026-34456

Reviactyl: OAuth account takeover via auto-linking

Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using a victim’s email address and gain full access to the victim's account without knowing their password. This results in a full account takeover with no prior authentication required. This issue has been patched in version 26.2.0-beta.5.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
C
H
U
-

Related Resources

No items found.

References

https://github.com/reviactyl/panel/releases/tag/v26.2.0-beta.5, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34456.json, https://github.com/reviactyl/panel/security/advisories/GHSA-8mcf-rp68-xhfg, https://nvd.nist.gov/vuln/detail/CVE-2026-34456, https://github.com/reviactyl/panel/commit/fe0c29fc62fefe354c9ab8936dfe30fdb586a896

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00455%
EPSS Percentile
0.38041%
Introduced Version
7fe69b32524018df04d793272f7bcdc0a964913e
Fix Available
62efb006f4096055c312d036c62819d697ff5ac4

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading