Authorization Bypass in OAuth Provider by Better Auth
CVE-2026-67332
5.3MEDIUM
What is CVE-2026-67332?
The OAuth Provider by Better Auth prior to version 1.7.0-beta.4 contains a vulnerability that allows unauthorized access to resources by failing to properly bind the access-token audience to the authorization grant. This defect enables malicious actors to engage in an OAuth flow, gaining access tokens that could potentially target unrelated resource servers. As a result, this can lead to unintended data exposure and authorization boundary violations, compromising the overall security framework of the application.
Affected Version(s)
oauth-provider 1.4.8 < 1.7.0-beta.4
oauth-provider 1.7.0-beta.4
