---
id: CVE-2026-67328
title: >-
  @better-auth/sso versions before 1.6.21 contain multiple authentication bypass
  vulnerabilities in SSO provider handling that allow attackers to sign in as
  arbitrary users
summary: >-
  @better-auth/sso versions before 1.6.21 contain multiple authentication bypass
  vulnerabilities in SSO provider handling that allow attackers to sign in as
  arbitrary users. Attackers can exploit domain verification parsing mismatches,
  orp…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-79
published: '2026-08-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:34:34.997'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67328'
references:
  - url: >-
      https://github.com/better-auth/better-auth/security/advisories/GHSA-prpr-5gj3-qqhg
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/better-auth-sso-before-account-takeover-via-sso
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00491
epssPercentile: 0.3956
ingestedAt: '2026-08-02T07:18:02.367Z'
---

## Overview

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoints to gain unauthorized session access and account takeover.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
