CVE-2026-67329

HIGH

@better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription

Title source: cna
STIX 2.1

Description

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the organization ID only from the request body and falls back to the caller's active organization from their session. When these differ, an authenticated member of multiple organizations can perform subscription actions (cancel, change plan, restore, billing portal access) against an organization they belong to but should not manage, and can access another organization's billing details including payment methods, invoices, and subscription state.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-h3rm-78g3-j7cp)
https://github.com/better-auth/better-auth/security/advisories/GHSA-h3rm-78g3-j7cp
Third Party Advisory third-party-advisory
VulnCheck Advisory: @better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription
https://www.vulncheck.com/advisories/better-auth-stripe-before-authorization-bypass-via-organization-subscription

Scores

CVSS v3 7.1
EPSS 0.0020
EPSS Percentile 9.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (4)
better-auth/stripe 1.4.11 - 1.6.21
better-auth/stripe 1.6.21
better-auth/stripe 1.7.0-beta.0 - 1.7.0-beta.10
better-auth/stripe 1.7.0-beta.10
Published Aug 01, 2026
Tracked Since Aug 01, 2026