Two-Factor Authentication Bypass in Better-Auth Plugin by Better-Auth
CVE-2026-67337
7.1HIGH
What is CVE-2026-67337?
Versions of Better-Auth prior to 1.4.9 are susceptible to a two-factor authentication bypass due to the session.cookieCache feature being enabled. Attackers holding valid primary credentials can exploit this flaw to access secure routes without undergoing the second-factor authentication process, through the manipulation of premature session cache mechanisms. This vulnerability poses a significant risk as it undermines the integrity of user authentication.
Affected Version(s)
better-auth 0 < 1.4.9
better-auth 1.4.9
