Authentication Bypass Vulnerabilities in @better-auth/sso from BetterAuth
CVE-2026-67328
8.6HIGH
What is CVE-2026-67328?
The @better-auth/sso component prior to version 1.6.21 is impacted by several authentication bypass vulnerabilities. These security weaknesses stem from improper handling of SSO provider mechanisms, enabling attackers to authenticate as arbitrary users. Specifically, the vulnerabilities arise from issues like domain verification parsing mismatches, unbound SAML assertions, orphaned provider accounts, and reflected XSS on logout endpoints. By exploiting these flaws, malicious actors can gain unauthorized session access, leading to potential account takeovers.
Affected Version(s)
sso 0 < 1.6.21
sso 1.7.0-beta.0 < 1.7.0-beta.10
sso 1.6.21
