CVE-2026-34456General(reviactyl / reviactyl)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch reviactyl reviactyl systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using a victim’s email address and gain full access to the victim's account without knowing their password. This results in a full account takeover with no prior authentication required. This issue has been patched in version 26.2.0-beta.5.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • reviactyl

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-02); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
reviactyl

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-01: 1Mentions · 2026-04-02: 4Mentions · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 104-0104-0204-07
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-024
General3Patch1
2026-04-071
Disclosure1
Full discourse6 posts
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-34456: Reviactyl OAuth Account Takeover - What It Means for Your Business and How to Respond https://hubs.li/Q049QN_X0

    Post summary

    The excerpt only announces the CVE and signals that the article will discuss its implications, with no concrete technical or exploit details provided.

    0000025
    28 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34456: CRITICAL] Vulnerability in Reviactyl game server management panel allows full account takeover via OAuth. Update to version 26.2.0-beta.5 to patch this critical security flaw.#cve,CVE-2026-34456,#cybersecurity https://cvefind.com/CVE-2026-34456

    Post summary

    CVE-2026-34456 is a critical vulnerability in the Reviactyl game server management panel that allows full account takeover via OAuth; operators are advised to update to version 26.2.0-beta.5 to address the issue.

    0000031
    617 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34456 Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-be… https://www.cve.org/CVERecord?id=CVE-2026-34456 ----- Traducción: CVE-2026-34456 Rev… http://infoflow.cloud`

    Post summary

    The post merely references CVE‑2026‑34456 with a link to the official CVE record, without providing technical details or exploitation information.

    0000055
    65 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34456 Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-be… https://www.cve.org/CVERecord?id=CVE-2026-34456

    Post summary

    The post mentions CVE‑2026‑34456 with minimal context, lacking evidence of PoC, exploit, active usage, patch information, or technical details.

    00000190
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-34456 - Critical Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability... https://www.thehackerwire.com/vulnerability/CVE-2026-34456/ https://t.co/UjaZULlGS2

    Post summary

    The post only announces CVE‑2026‑34456 as a critical issue for Reviactyl and links to external articles, providing no detailed technical info, exploit code, or patch guidance.

    0000085
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34456: Reviactyl: OAuth account takeove... OAuth auto-linking by email alone = instant account takeover; just register the victim's email on any supported provide... https://zerodaysignal.com/vulnerability/CVE-2026-34456 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-34456 exposes that OAuth auto‑linking by email enables instant account takeover in Reviactyl, with a zero‑day signal link provided for more details.

    0000075
    194 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appreviactylreviactyl26.2.0--
Appreviactylreviactyl26.2.0--
Appreviactylreviactyl26.2.0--
Appreviactylreviactyl26.2.0--

Explore more