{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/better-auth--1.1.3--1.6.22-and--1.7.0-beta.0--1.7.0-beta.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-67327"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["better-auth (\u003e= 1.1.3, \u003c 1.6.22 and \u003e= 1.7.0-beta.0, \u003c 1.7.0-beta.10)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["better-auth"],"content_html":"\u003cp\u003eThe better-auth library versions 1.1.3 through 1.6.21, and specific pre-release versions 1.7.0-beta.0 through 1.7.0-beta.9, contain a critical vulnerability (CVE-2026-67327) that facilitates account takeover through pre-account hijacking. This vulnerability occurs when the application configuration has open email/password registration enabled. An attacker can preemptively register an account using a target's email address and an attacker-controlled password. While the account remains unverified at this stage, the vulnerability triggers when the legitimate user initiates a passwordless authentication flow, such as magic-link or email-OTP. Upon successful verification of the user's identity via these methods, the system marks the account as verified but fails to clear the attacker-provided credentials or invalidate existing unauthorized sessions. Consequently, the attacker retains persistent access to the account using their original password. This issue is resolved in version 1.6.22 and 1.7.0-beta.10.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete account takeover, enabling unauthorized access to user data and account functions. This flaw poses a high risk to organizations relying on better-auth for identity management, particularly those allowing open registration. If left unpatched, victims who attempt to use passwordless authentication on a pre-hijacked account will unknowingly provide attackers with continued, verified access to their sensitive information.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the better-auth library to version 1.6.22 or 1.7.0-beta.10 or later immediately to mitigate the underlying flaw identified in CVE-2026-67327.\u003c/li\u003e\n\u003cli\u003eReview application authentication logs for accounts where email/password registration and passwordless login flows occur sequentially from different source IP addresses or session identifiers.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable open email/password registration in the better-auth configuration to prevent the initial account creation stage of this attack.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T13:53:04Z","date_published":"2026-08-01T13:53:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-takeover/","summary":"The better-auth library is vulnerable to account takeover (CVE-2026-67327) when open email/password registration is enabled, allowing attackers to maintain persistent access after a victim authenticates via passwordless flows.","title":"Account Takeover Vulnerability in better-auth via Pre-Account Hijacking","url":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-takeover/"}],"language":"en","title":"CraftedSignal Threat Feed - Better-Auth (\u003e= 1.1.3, \u003c 1.6.22 and \u003e= 1.7.0-Beta.0, \u003c 1.7.0-Beta.10)","version":"https://jsonfeed.org/version/1.1"}