---
id: CVE-2026-9084
title: >-
  MISP’s OIDC authentication plugin allowed automatic linking of an OIDC
  identity to an existing local user account based on the email claim when the
  local account had no stored sub value
summary: >-
  MISP’s OIDC authentication plugin allowed automatic linking of an OIDC
  identity to an existing local user account based on the email claim when the
  local account had no stored sub value. Under insecure or untrusted IdP
  configurations whe…
severity: none
cwe:
  - CWE-287
published: '2026-05-20'
updated: '2026-07-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9084'
references:
  - url: >-
      https://github.com/MISP/MISP/commit/71f5662c1b5886613d2cd5c72fd93bb4ca6fa172
    label: 5a6e4751-2f3f-4070-9419-94fb35b644e8
tags:
  - nvd
epss: 0.00221
epssPercentile: 0.11225
ingestedAt: '2026-07-23T12:17:55.294Z'
---

## Overview

MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an attacker with a valid OIDC token could assert a victim’s email address and authenticate as that user, leading to account takeover.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
