{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/sso/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-67328"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["sso"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","sso","account-takeover","cve-2026-67328"],"_cs_type":"advisory","_cs_vendors":["better-auth"],"content_html":"\u003cp\u003eThe @better-auth/sso library is affected by multiple authentication bypass vulnerabilities in versions prior to 1.6.21 and specific beta versions (1.7.0-beta.0 through 1.7.0-beta.9). These flaws exist within the SSO provider handling logic, enabling attackers to sign in as arbitrary users. The vulnerabilities stem from disparate issues including domain verification parsing mismatches, improper handling of orphaned provider accounts, unbound SAML assertions, and reflected Cross-Site Scripting (XSS) on logout endpoints. By leveraging these weaknesses, an attacker can manipulate the authentication flow to gain unauthorized session access and execute full account takeover. Given the library's role in facilitating SSO integrations, these vulnerabilities pose a significant risk of unauthorized access to enterprise applications and user data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an application utilizing a vulnerable version of @better-auth/sso.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates an authentication request to the SSO provider.\u003c/li\u003e\n\u003cli\u003eThe attacker intercepts or modifies the response, exploiting domain verification parsing mismatches or injecting an unbound SAML assertion.\u003c/li\u003e\n\u003cli\u003eAlternatively, the attacker triggers a reflected XSS on the logout endpoint to steal session identifiers or manipulate session state.\u003c/li\u003e\n\u003cli\u003eThe @better-auth/sso library incorrectly validates the forged or manipulated SSO assertion.\u003c/li\u003e\n\u003cli\u003eThe application grants the attacker an authenticated session associated with the target user's identity.\u003c/li\u003e\n\u003cli\u003eThe attacker accesses the application as the target user, achieving unauthorized access or complete account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthorized access to user accounts, enabling attackers to view private data, perform unauthorized actions on behalf of users, or elevate privileges if the account is an administrator. This impacts all applications and services that rely on the @better-auth/sso library for authentication, potentially exposing thousands of user sessions depending on the scale of the deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade @better-auth/sso to version 1.6.21 or 1.7.0-beta.10 immediately to remediate the vulnerabilities.\u003c/li\u003e\n\u003cli\u003eReview authentication logs for unusual session activity or authentication requests originating from unexpected SSO providers.\u003c/li\u003e\n\u003cli\u003eAudit custom authentication logic that integrates with @better-auth/sso to ensure strict validation of SAML assertions and SSO responses.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for XSS patterns on logout endpoints as a compensatory measure while patching.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T13:53:11Z","date_published":"2026-08-01T13:53:11Z","id":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-sso-bypass/","summary":"Multiple authentication bypass vulnerabilities in @better-auth/sso allow attackers to perform account takeovers by exploiting flaws in SSO provider handling.","title":"Authentication Bypass in @better-auth/sso","url":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-sso-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Sso","version":"https://jsonfeed.org/version/1.1"}