Authorization Bypass in Better Auth Stripe Integration Affects Multiple Organizations
CVE-2026-67329

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67329?

The Better Auth Stripe integration has a vulnerability that allows an authenticated user with access to multiple organizations to execute unauthorized subscription actions. The middleware mismanages organization ID validation, enabling users to perform actions such as canceling or changing subscriptions and accessing sensitive billing details of other organizations. This flaw occurs due to a discrepancy between the organization ID in the request query string and the active session organization. Attackers can exploit this vulnerability to gain unauthorized access to billing methods, invoices, and subscription states across multiple organizations.

Affected Version(s)

stripe 1.4.11 < 1.6.21

stripe 1.7.0-beta.0 < 1.7.0-beta.10

stripe 1.6.21

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.