better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via… (CVE-2026-67327)
better-auth versions from 1.1.3 up to but not including 1.6.22, and pre-release versions from 1.7.0-beta.0 up to but not including 1.7.0-beta.10, contain a vulnerability that allows account takeover via a pre-account hijacking attack. This occurs when open email/password registration is enabled and an attacker registers an account with the victim's email and a chosen password. Later, when the legitimate user signs in using magic-link or email-OTP passwordless methods, the account becomes verified without removing the attacker's password or revoking sessions, allowing persistent unauthorized access. The issue is fixed in versions 1.6.22 and 1.7.0-beta.10.
AI Analysis
Technical Summary
The vulnerability in better-auth affects versions >=1.1.3 <1.6.22 and pre-release versions >=1.7.0-beta.0 <1.7.0-beta.10. It enables an attacker to hijack accounts by registering with the victim's email and a password before the victim verifies the account. When the victim later authenticates via passwordless methods (magic-link or email-OTP), the system marks the account as verified but does not remove the attacker's password or revoke existing sessions. This flaw allows the attacker to maintain persistent access to the victim's account. The vulnerability is tracked as CVE-2026-67327 with a CVSS 3.1 score of 8.3 (high severity). It is fixed in versions 1.6.22 and 1.7.0-beta.10.
Potential Impact
Successful exploitation results in account takeover, allowing an attacker to gain persistent unauthorized access to user accounts. The attacker’s password remains valid even after the legitimate user verifies the account via passwordless sign-in, compromising confidentiality, integrity, and availability of the affected accounts.
Mitigation Recommendations
Upgrade affected better-auth versions to 1.6.22 or later, or to 1.7.0-beta.10 or later for pre-release versions. These versions contain the official fix that removes the vulnerability. No other mitigation is indicated by the vendor advisory.
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via… (CVE-2026-67327)
Description
better-auth versions from 1.1.3 up to but not including 1.6.22, and pre-release versions from 1.7.0-beta.0 up to but not including 1.7.0-beta.10, contain a vulnerability that allows account takeover via a pre-account hijacking attack. This occurs when open email/password registration is enabled and an attacker registers an account with the victim's email and a chosen password. Later, when the legitimate user signs in using magic-link or email-OTP passwordless methods, the account becomes verified without removing the attacker's password or revoking sessions, allowing persistent unauthorized access. The issue is fixed in versions 1.6.22 and 1.7.0-beta.10.
CVSS v3.1
Score 8.3high
Affected software
pkg:github/better-auth/better-authRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in better-auth affects versions >=1.1.3 <1.6.22 and pre-release versions >=1.7.0-beta.0 <1.7.0-beta.10. It enables an attacker to hijack accounts by registering with the victim's email and a password before the victim verifies the account. When the victim later authenticates via passwordless methods (magic-link or email-OTP), the system marks the account as verified but does not remove the attacker's password or revoke existing sessions. This flaw allows the attacker to maintain persistent access to the victim's account. The vulnerability is tracked as CVE-2026-67327 with a CVSS 3.1 score of 8.3 (high severity). It is fixed in versions 1.6.22 and 1.7.0-beta.10.
Potential Impact
Successful exploitation results in account takeover, allowing an attacker to gain persistent unauthorized access to user accounts. The attacker’s password remains valid even after the legitimate user verifies the account via passwordless sign-in, compromising confidentiality, integrity, and availability of the affected accounts.
Mitigation Recommendations
Upgrade affected better-auth versions to 1.6.22 or later, or to 1.7.0-beta.10 or later for pre-release versions. These versions contain the official fix that removes the vulnerability. No other mitigation is indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9wm3-rh5c-fc37
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-67327"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6e6293bf32cb7a344f68b7
Added to database: 08/01/2026, 21:18:11 UTC
Last enriched: 08/01/2026, 21:20:55 UTC
Last updated: 08/02/2026, 01:57:52 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.