Insecure Cryptographic Defaults in better-auth Product by Better-Auth
CVE-2026-67336

9.4CRITICAL

Key Information:

Vendor
CVE Published:
1 August 2026

What is CVE-2026-67336?

Better-auth versions before 1.6.11 exhibit insecure cryptographic defaults within their oidcProvider and mcp plugins. These vulnerabilities arise from the promotion of the 'none' algorithm and the acceptance of plain PKCE by default. Attackers can exploit this misconfiguration, leveraging algorithm negotiation to accept unsigned tokens or to intercept authorization codes when using PKCE in plain format instead of the recommended S256 method. This can potentially undermine the integrity and confidentiality of authentication processes.

Affected Version(s)

better-auth 0 < 1.6.11

better-auth 1.6.11

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

subhanUmer
.