Account Takeover Vulnerability in Better-Auth Product by Better-Auth Vendor
CVE-2026-67327

8.7HIGH

Key Information:

Vendor
CVE Published:
1 August 2026

What is CVE-2026-67327?

The Better-Auth application is vulnerable to an account takeover exploit involving pre-account hijacking through its magic-link and email-OTP sign-in features. When users enable open email/password registration, an attacker can register an account using a victim's email along with a selected password, leaving the account unverified. If the actual owner later attempts to sign in using the magic-link or passwordless email-OTP, the account is auto-verified without revoking the attacker's previously set password. This oversight allows the attacker to retain continuous access to the victim's account, leading to serious security breaches. Users should upgrade to version 1.6.22 or 1.7.0-beta.10 to mitigate this risk.

Affected Version(s)

better-auth 1.1.3 < 1.6.22

better-auth 1.7.0-beta.0 < 1.7.0-beta.10

better-auth 1.6.22

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.