Account Takeover Vulnerability in Better-Auth Product by Better-Auth Vendor
CVE-2026-67327
What is CVE-2026-67327?
The Better-Auth application is vulnerable to an account takeover exploit involving pre-account hijacking through its magic-link and email-OTP sign-in features. When users enable open email/password registration, an attacker can register an account using a victim's email along with a selected password, leaving the account unverified. If the actual owner later attempts to sign in using the magic-link or passwordless email-OTP, the account is auto-verified without revoking the attacker's previously set password. This oversight allows the attacker to retain continuous access to the victim's account, leading to serious security breaches. Users should upgrade to version 1.6.22 or 1.7.0-beta.10 to mitigate this risk.
Affected Version(s)
better-auth 1.1.3 < 1.6.22
better-auth 1.7.0-beta.0 < 1.7.0-beta.10
better-auth 1.6.22
