Intel

AIKIDO-2026-10364

drupal/openid_connect is vulnerable to Access bypass

Access bypassCVE-2026-3532 Published Mar 16, 2026

35

Low Risk

This Affects:

PHPdrupal/openid_connect
1.0.0 - 1.4.0
Fixed in 1.5.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by an access control bypass vulnerability due to insufficient validation of the uniqueness of certain user fields depending on the database engine and its collation settings. Because uniqueness checks may behave inconsistently across different database configurations, an attacker could register an account using the same email address as an existing user. This could lead to authentication or account-association confusion and potential data integrity issues.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/openid_connect is vulnerable to Access bypass in versions 1.0.0 - 1.4.0.

How to fix this

Upgrade the drupal/openid_connect library to the patch version and check existing accounts affected by this issue.