The OpenID module is not a compliant implementation of the OpenID Authentication 2.0 specification. An implementation error allows a user to access the account of another user when they share the same OpenID 2.0 provider.
This issue affects Drupal 6.x only.
Vendor Status:
Drupal issued an update for this vulnerability