OAuth State Validation Bypass in better-auth by Better Auth
CVE-2026-67335

6MEDIUM

Key Information:

Vendor
CVE Published:
1 August 2026

What is CVE-2026-67335?

Versions of better-auth prior to 1.6.2 are susceptible to a vulnerability that allows attackers to bypass OAuth state validation. This occurs when cookie-backed state storage is utilized without PKCE, leading to a scenario where the OAuth state parameter is not properly validated against the stored nonce. As a result, attackers can craft a state parameter and provide a malicious authorization code, enabling them to forge authenticated sessions linked to an external identity or to associate attacker-controlled accounts with victim profiles. It is essential for users of the affected versions to update to the latest release to mitigate this significant security risk.

Affected Version(s)

better-auth 0 < 1.6.2

better-auth 1.6.2

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jvr2022
alavesa
.