


Perceptive Security
SOC/SIEM Consultancy

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hij…
Published:
1 augustus 2026 om 00:00:00
Alert date:
1 augustus 2026 om 16:10:47
Source:
nvd.nist.gov
Identity & Access, Web Technologies
CVE-2026-67327 affects better-auth versions >= 1.1.3 and < 1.6.22, as well as pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10. The vulnerability enables account takeover through a pre-account hijacking technique. An attacker registers an account using a victim's email address with an attacker-chosen password before the victim creates their account. The attacker's account remains unverified but retains the attacker-set password. When the legitimate victim later authenticates via magic-link or email-OTP passwordless flows, the account is marked as verified but the pre-existing attacker password is not removed and existing sessions are not revoked. This grants the attacker persistent access to the victim's account. The vulnerability requires open email/password registration to be enabled. Fixes are available in versions 1.6.22 and 1.7.0-beta.10.
Technical details
Mitigation steps:
Affected products:
better-auth
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67327
https://github.com/better-auth/better-auth/security/advisories/GHSA-qq9h-g4jm-xgf3
https://www.vulncheck.com/advisories/better-auth-before-account-takeover-via-magic-link-email-otp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
