PT-2026-67307 · Unknown · Better Auth
CVE-2026-67327
·
Published
2026-07-24
·
Updated
2026-08-01
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
better-auth versions 1.1.3 through 1.6.21
better-auth versions 1.7.0-beta.0 through 1.7.0-beta.9
Description
A pre-account hijacking flaw allows account takeover when open email and password registration is enabled alongside magic-link or email-OTP sign-in. An attacker can register an account using a victim's email address and a password of their choice. While the account remains unverified and inaccessible to the attacker initially, the situation changes when the legitimate owner signs in using a passwordless flow (magic-link or email-OTP). This action marks the account as verified but fails to remove the attacker's pre-set password or revoke existing sessions. Consequently, the attacker retains persistent password access to the account, enabling them to read or modify the victim's data or lock the owner out entirely.
Recommendations
Update better-auth to version 1.6.22 or later.
Update better-auth to version 1.7.0-beta.10 or later.
As a temporary mitigation, require email verification before accepting any password on an account or implement a process to quickly remove unverified accounts.
Exploit
Fix
Insufficient Verification of Data Authenticity
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Better Auth