PT-2026-81905 · Npm · @Better-Auth/Sso

·

CVE-2026-80192

·

Published

2026-08-25

·

Updated

2026-08-29

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @better-auth/sso versions prior to 1.4.8 @better-auth/sso versions prior to 1.6.27 @better-auth/sso versions prior to 1.7.0-rc.5
Description Two domain-ownership flaws exist when the SSO plugin is active. If domain verification is disabled, automatic organization assignment accepts unverified provider domains. This allows an authenticated organization owner or administrator to register an SSO provider for any domain, causing users with matching email domains to be added to the attacker's organization with default member permissions. If domain verification is enabled, a race condition occurs between the 'verify-domain' and 'update-provider' endpoints, which can apply a completed DNS proof to an incorrect domain. When combined with implicit account linking, this allows an attacker-controlled identity provider to be linked to an existing user account. The organization plugin must also be enabled for the organization assignment path to be exploited.
Recommendations Update @better-auth/sso to version 1.4.8 or later for the 1.4.x line. Update @better-auth/sso to version 1.6.27 or later. Update @better-auth/sso to version 1.7.0-rc.5 or later for the 1.7 prerelease line.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80192
GHSA-8C5H-WX78-2CFG

Affected Products

@Better-Auth/Sso