Description
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address and an attacker-chosen password; the account remains unverified. When the legitimate owner later signs in via the magic-link or email-OTP passwordless flow, the account is marked verified without removing the pre-existing password or revoking existing sessions, so the attacker's password remains valid, granting persistent access to the victim's account. Fixed in 1.6.22 and 1.7.0-beta.10.
Published: 2026-08-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in better‑auth allows an attacker to hijack an account by registering the victim’s e‑mail and a chosen password. When the legitimate user later signs in using magic‑link or email‑OTP, the account is marked verified but the attacker’s password remains valid, giving the attacker persistent access. This bypasses authentication and is described as CWE‑287.

Affected Systems

The affected product is better‑auth OAuth Provider for Node.js. All released versions from 1.1.3 up to, but not including, 1.6.22 and the pre‑release <1.7.0‑beta.10 are vulnerable. These versions expose a pre‑account creation path when open e‑mail/password registration is enabled.

Risk and Exploitability

The CVSS score is 8.7, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs the victim’s e‑mail address and the ability to submit a registration request; no privileged access is required. Because the attack path is part of the normal sign‑in flow, it can be exploited remotely with minimal effort, making it a high‑risk exposure until mitigated.

Generated by OpenCVE AI on August 2, 2026 at 03:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade better‑auth to version 1.6.22 or later (or 1.7.0‑beta.10).
  • Disable or restrict the open e‑mail/password registration feature until the upgrade is applied.
  • Review account‑creation logs for suspicious registrations and verify that unexpected e‑mail addresses are not being registered.

Generated by OpenCVE AI on August 2, 2026 at 03:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Better-auth better Auth
Vendors & Products Better-auth better Auth

Sat, 01 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address and an attacker-chosen password; the account remains unverified. When the legitimate owner later signs in via the magic-link or email-OTP passwordless flow, the account is marked verified without removing the pre-existing password or revoking existing sessions, so the attacker's password remains valid, granting persistent access to the victim's account. Fixed in 1.6.22 and 1.7.0-beta.10.
Title better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP
First Time appeared Better-auth
Better-auth better-auth\/oauth-provider
Weaknesses CWE-287
CPEs cpe:2.3:a:better-auth:better-auth\/oauth-provider:*:*:*:*:*:node.js:*:*
Vendors & Products Better-auth
Better-auth better-auth\/oauth-provider
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Better-auth Better-auth\/oauth-provider Better Auth
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-01T12:22:17.753Z

Reserved: 2026-07-29T13:07:21.184Z

Link: CVE-2026-67327

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T03:15:03Z

Weaknesses