Impact
The flaw allows an authenticated organization owner or administrator to register an SSO provider for an arbitrary domain. When domain verification is disabled, users whose email domains match the provider are automatically added to the attacker's organization with default permissions. With domain verification enabled, a race condition can swap domain proof between requests, enabling an attacker to link an attacker‑controlled identity provider to an existing user account. The weakness is a control‑flow bypass that undermines domain ownership validation (CWE-287).
Affected Systems
better‑auth/sso is affected. Versions prior to 1.6.27 in the main branch, before 1.4.8 in the 1.4.x line, and before 1.7.0‑rc.5 in the 1.7 prerelease line are vulnerable. The issue requires the SSO plugin and, for the organization‑assignment path, the organization plugin to be enabled.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity. EPSS data is not available, so the current exploitation probability is unknown but the lack of mitigation guidance suggests it is feasible in practice. The vulnerability is not listed in CISA’s KEV catalog. Attackers need legitimate administrative credentials within an organization and must enable or exploit the organization‑assignment feature. The race condition in the verify‑domain and update‑provider endpoints provides a practical attack vector when domain verification is turned on.
OpenCVE Enrichment