CVE-2026-67328 Details
Description
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoints to gain unauthorized session access and account takeover.
Multiple authentication bypass vulnerabilities have been identified in the @better-auth/sso package, affecting versions prior to 1.6.21 and certain 1.7.0 beta releases. These vulnerabilities allow attackers to sign in as arbitrary users, leading to unauthorized access and account takeover. The issues arise from mismatches in domain verification parsing, orphaned provider accounts, unbound SAML assertions, and reflected cross-site scripting on logout endpoints.
Users are advised to upgrade to @better-auth/sso version 1.6.21 or later, or to version 1.7.0-beta.10 or later. If an immediate upgrade is not possible, SSO registration can be disabled or put under admin review, and implicit account linking can be turned off. For SAML, it is recommended to use pre-validated default SSO providers and to leave the single logout feature off unless necessary.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 1, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/better-auth/better-auth/security/advisories/GHSA-prpr-5gj3-qqhg | [email protected] | AdvisoryRemedyVendor |
| https://www.vulncheck.com/advisories/better-auth-sso-before-account-takeover-via-sso | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| better-auth/sso | <= 1.6.20 (semver) >= 1.7.0-beta.0, < 1.7.0-beta.10 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2026 | New CVE Received | [email protected] |
Volerion