Insecure Direct Object Reference in Better-Auth Passkey Deletion Endpoint
CVE-2025-71400

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
2 August 2026

What is CVE-2025-71400?

The better-auth passkey versions prior to 1.4.0 are susceptible to an insecure direct object reference vulnerability located in the passkey deletion endpoint. This flaw permits authenticated users to maliciously delete arbitrary passkeys by ID. An attacker holding a valid session can craft tailored requests directed at the delete-passkey endpoint, sequentially targeting passkey IDs to delete other users’ passkeys, potentially leading to serious breaches of user data privacy.

Affected Version(s)

passkey 0 < 1.4.0

passkey 1.4.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

goksan
.