CVE-2026-67334

LOW

better-auth Stale Sessions Persist After User Deletion

Title source: cna
STIX 2.1

Description

better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-2vg6-77g8-24mp)
https://github.com/better-auth/better-auth/security/advisories/GHSA-2vg6-77g8-24mp
Third Party Advisory third-party-advisory
VulnCheck Advisory: better-auth Stale Sessions Persist After User Deletion
https://www.vulncheck.com/advisories/better-auth-stale-sessions-persist-after-user-deletion

Scores

CVSS v3 3.8
EPSS 0.0020
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-459
Status published
Products (3)
better-auth/better-auth 0.3.4 - 1.6.11
better-auth/better-auth 1.6.0 - 1.6.11
better-auth/better-auth 1.6.11
Published Aug 01, 2026
Tracked Since Aug 01, 2026