Description
@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization owner/administrator to register an SSO provider for an arbitrary domain and have users with matching email domains added to the attacker's organization with default member permissions. When domain verification is enabled, a race condition between the verify-domain and update-provider endpoints can apply completed DNS proof to a different domain; combined with implicit account linking, this can link an attacker-controlled identity provider to an existing user account. Exploitation requires the SSO plugin (and, for the org-assignment path, the organization plugin) with the relevant configuration enabled.
Published: 2026-08-25
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows an authenticated organization owner or administrator to register an SSO provider for an arbitrary domain. When domain verification is disabled, users whose email domains match the provider are automatically added to the attacker's organization with default permissions. With domain verification enabled, a race condition can swap domain proof between requests, enabling an attacker to link an attacker‑controlled identity provider to an existing user account. The weakness is a control‑flow bypass that undermines domain ownership validation (CWE-287).

Affected Systems

better‑auth/sso is affected. Versions prior to 1.6.27 in the main branch, before 1.4.8 in the 1.4.x line, and before 1.7.0‑rc.5 in the 1.7 prerelease line are vulnerable. The issue requires the SSO plugin and, for the organization‑assignment path, the organization plugin to be enabled.

Risk and Exploitability

With a CVSS score of 8.6 the vulnerability is considered high severity. EPSS data is not available, so the current exploitation probability is unknown but the lack of mitigation guidance suggests it is feasible in practice. The vulnerability is not listed in CISA’s KEV catalog. Attackers need legitimate administrative credentials within an organization and must enable or exploit the organization‑assignment feature. The race condition in the verify‑domain and update‑provider endpoints provides a practical attack vector when domain verification is turned on.

Generated by OpenCVE AI on August 26, 2026 at 01:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch to better‑auth/sso version 1.6.27 or later.
  • If the patch cannot be applied immediately, enable domain verification to prevent automatic organization assignment of unverified provider domains.
  • If the organization plugin is in use and an upgrade is delayed, consider disabling the organization‑assignment feature or restricting administrative permissions until the fix is applied.
  • Monitor SSO provider registrations and account linking logs for unexpected changes and investigate promptly.

Generated by OpenCVE AI on August 26, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Better-auth sso
Vendors & Products Better-auth sso

Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization owner/administrator to register an SSO provider for an arbitrary domain and have users with matching email domains added to the attacker's organization with default member permissions. When domain verification is enabled, a race condition between the verify-domain and update-provider endpoints can apply completed DNS proof to a different domain; combined with implicit account linking, this can link an attacker-controlled identity provider to an existing user account. Exploitation requires the SSO plugin (and, for the org-assignment path, the organization plugin) with the relevant configuration enabled.
Title better-auth SSO before 1.6.27 Domain Ownership Authentication Bypass
First Time appeared Better-auth
Better-auth better-auth\/sso
Weaknesses CWE-287
CPEs cpe:2.3:a:better-auth:better-auth\/sso:*:*:*:*:*:*:*:*
cpe:2.3:a:better-auth:better-auth\/sso:-:*:*:*:*:*:*:*
Vendors & Products Better-auth
Better-auth better-auth\/sso
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Better-auth Better-auth\/sso Sso
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-25T23:19:00.371Z

Reserved: 2026-08-25T23:14:37.730Z

Link: CVE-2026-80192

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T02:00:04Z

Weaknesses