top of page
perceptive_background_267k.jpg

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hij…

Published:

1 August 2026 at 00:00:00

Alert date:

1 August 2026 at 16:10:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies

CVE-2026-67327 affects better-auth versions >= 1.1.3 and < 1.6.22, as well as pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10. The vulnerability enables account takeover through a pre-account hijacking technique. An attacker registers an account using a victim's email address with an attacker-chosen password before the victim creates their account. The attacker's account remains unverified but retains the attacker-set password. When the legitimate victim later authenticates via magic-link or email-OTP passwordless flows, the account is marked as verified but the pre-existing attacker password is not removed and existing sessions are not revoked. This grants the attacker persistent access to the victim's account. The vulnerability requires open email/password registration to be enabled. Fixes are available in versions 1.6.22 and 1.7.0-beta.10.

Technical details

Mitigation steps:

Affected products:

better-auth

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page