CVE-2026-45337
HIGHBetter Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
Title source: cnaDescription
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim the row and POST /device/approve and POST /device/deny short-circuit when userId is unset, allowing an authenticated attacker who learns a valid user_code to bind the polling device to the attacker's account or deny the legitimate flow. This issue is fixed in version 1.6.11.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/better-auth/better-auth/security/advisories/GHSA-cq3f-vc6p-68fh
X_Refsource_Misc x_refsource_misc
https://github.com/better-auth/better-auth/pull/9573
X_Refsource_Misc x_refsource_misc
https://github.com/better-auth/better-auth/commit/99a254a79b59d5a3f5ca2123260118cddb5beed7
X_Refsource_Misc x_refsource_misc
https://github.com/better-auth/better-auth/releases/tag/v1.6.11
Scores
CVSS v3
7.6
EPSS
0.0014
EPSS Percentile
3.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-285
CWE-345
Status
published
Products (2)
better-auth/better-auth
>= 1.6.0, < 1.6.11
better-auth/better_auth
1.6.0 - 1.6.11
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026