HIGH🇵🇱 Wersja polska

CVE-2026-53516

CVSS 8.3v3.1pub. 2026-07-15upd. 2026-07-21

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user row's emailVerified field to also be true, allowing an attacker who pre-registers a victim email through /sign-up/email to bind the victim's OAuth identity to the attacker's account. The same primitive affects one-tap, and emailAndPassword.requireEmailVerification: true does not mitigate the link-time verification change. This issue is fixed in version 1.6.11.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
  • Better Auth

    APP
    Better-Auth
    < 1.6.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-53513CRITICAL9.6PL ✓same product

SSRF w Better Auth — niezweryfikowane endpointy OIDC w pluginie SSO

CVE-2026-53512CRITICAL9.1PL ✓same product

Better Auth: pominięcie weryfikacji client_secret w endpointach OAuth token

CVE-2026-53518HIGH7.6PL ✓same product

Race condition w Better Auth umożliwia wielokrotne użycie kodu autoryzacyjnego OAuth2

CVE-2026-45337HIGH7.6PL ✓same product

Better Auth: błędna autoryzacja w pluginie deviceAuthorization umożliwia przejęcie sesji urządzenia

CVE-2026-53515HIGH7.1PL ✓same product

Better Auth SSO: nieautoryzowana rejestracja dostawcy SSO przez zwykłego członka organizacji