GitHub Security Advisory (GHSA-prpr-5gj3-qqhg)Vendor advisory
https://github.com/better-auth/better-auth/security/advisories/GHSA-prpr-5gj3-qqhg CVE-2026-67328
HIGH
@better-auth/sso before 1.6.21 Account Takeover via SSO
Record summary
CVE-2026-67328 has a selected CVSS score of 8.6 (high).
Description
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoints to gain unauthorized session access and account takeover.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 1.6.21 | affected |
| 1.6.21 | unaffected | ||
| 1.7.0-beta.0 to < 1.7.0-beta.10 | affected | ||
| 1.7.0-beta.10 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-67328 VulnCheck Advisory: @better-auth/sso before 1.6.21 Account Takeover via SSOThird-party advisory
https://www.vulncheck.com/advisories/better-auth-sso-before-account-takeover-via-sso