CVE-2026-67328 PUBLISHED

@better-auth/sso before 1.6.21 Account Takeover via SSO

Assigner: VulnCheck
Reserved: 29.07.2026 Published: 01.08.2026 Updated: 01.08.2026

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoints to gain unauthorized session access and account takeover.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor better-auth
Product sso
Versions Default: unaffected
  • affected from 0 to 1.6.21 (excl.)
  • Version 1.6.21 is unaffected
Vendor better-auth
Product sso
Versions Default: unaffected
  • affected from 1.7.0-beta.0 to 1.7.0-beta.10 (excl.)
  • Version 1.7.0-beta.10 is unaffected

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE