Authorization Bypass in OAuth Provider by Better Auth
CVE-2026-67332

5.3MEDIUM

Key Information:

Vendor
CVE Published:
1 August 2026

What is CVE-2026-67332?

The OAuth Provider by Better Auth prior to version 1.7.0-beta.4 contains a vulnerability that allows unauthorized access to resources by failing to properly bind the access-token audience to the authorization grant. This defect enables malicious actors to engage in an OAuth flow, gaining access tokens that could potentially target unrelated resource servers. As a result, this can lead to unintended data exposure and authorization boundary violations, compromising the overall security framework of the application.

Affected Version(s)

oauth-provider 1.4.8 < 1.7.0-beta.4

oauth-provider 1.7.0-beta.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dvanmali
.