<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Better-Auth (&gt;= 1.1.3, &lt; 1.6.22 and &gt;= 1.7.0-Beta.0, &lt; 1.7.0-Beta.10) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/better-auth--1.1.3--1.6.22-and--1.7.0-beta.0--1.7.0-beta.10/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 01 Aug 2026 13:53:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/better-auth--1.1.3--1.6.22-and--1.7.0-beta.0--1.7.0-beta.10/feed.xml" rel="self" type="application/rss+xml"/><item><title>Account Takeover Vulnerability in better-auth via Pre-Account Hijacking</title><link>https://feed.craftedsignal.io/briefs/2026-08-better-auth-takeover/</link><pubDate>Sat, 01 Aug 2026 13:53:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-better-auth-takeover/</guid><description>The better-auth library is vulnerable to account takeover (CVE-2026-67327) when open email/password registration is enabled, allowing attackers to maintain persistent access after a victim authenticates via passwordless flows.</description><content:encoded><![CDATA[<p>The better-auth library versions 1.1.3 through 1.6.21, and specific pre-release versions 1.7.0-beta.0 through 1.7.0-beta.9, contain a critical vulnerability (CVE-2026-67327) that facilitates account takeover through pre-account hijacking. This vulnerability occurs when the application configuration has open email/password registration enabled. An attacker can preemptively register an account using a target's email address and an attacker-controlled password. While the account remains unverified at this stage, the vulnerability triggers when the legitimate user initiates a passwordless authentication flow, such as magic-link or email-OTP. Upon successful verification of the user's identity via these methods, the system marks the account as verified but fails to clear the attacker-provided credentials or invalidate existing unauthorized sessions. Consequently, the attacker retains persistent access to the account using their original password. This issue is resolved in version 1.6.22 and 1.7.0-beta.10.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for complete account takeover, enabling unauthorized access to user data and account functions. This flaw poses a high risk to organizations relying on better-auth for identity management, particularly those allowing open registration. If left unpatched, victims who attempt to use passwordless authentication on a pre-hijacked account will unknowingly provide attackers with continued, verified access to their sensitive information.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the better-auth library to version 1.6.22 or 1.7.0-beta.10 or later immediately to mitigate the underlying flaw identified in CVE-2026-67327.</li>
<li>Review application authentication logs for accounts where email/password registration and passwordless login flows occur sequentially from different source IP addresses or session identifiers.</li>
<li>If immediate patching is not possible, disable open email/password registration in the better-auth configuration to prevent the initial account creation stage of this attack.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>