Authorization Bypass in Better Auth Stripe Integration Affects Multiple Organizations
CVE-2026-67329
7.1HIGH
What is CVE-2026-67329?
The Better Auth Stripe integration has a vulnerability that allows an authenticated user with access to multiple organizations to execute unauthorized subscription actions. The middleware mismanages organization ID validation, enabling users to perform actions such as canceling or changing subscriptions and accessing sensitive billing details of other organizations. This flaw occurs due to a discrepancy between the organization ID in the request query string and the active session organization. Attackers can exploit this vulnerability to gain unauthorized access to billing methods, invoices, and subscription states across multiple organizations.
Affected Version(s)
stripe 1.4.11 < 1.6.21
stripe 1.7.0-beta.0 < 1.7.0-beta.10
stripe 1.6.21
