CVE-2026-67327
Received Received - Intake

Account Takeover via Pre-Account Hijacking in better-auth

Vulnerability report for CVE-2026-67327, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: VulnCheck

Description

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address and an attacker-chosen password; the account remains unverified. When the legitimate owner later signs in via the magic-link or email-OTP passwordless flow, the account is marked verified without removing the pre-existing password or revoking existing sessions, so the attacker's password remains valid, granting persistent access to the victim's account. Fixed in 1.6.22 and 1.7.0-beta.10.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
better-auth better-auth From 1.1.3 (inc) to 1.6.22 (exc)
better-auth better-auth From 1.7.0-beta.0 (inc) to 1.7.0-beta.10 (exc)
better-auth better-auth 1.6.22
better-auth better-auth 1.7.0-beta.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an account takeover issue in better-auth versions between 1.1.3 and 1.6.22 (and pre-release 1.7.0-beta.0 to 1.7.0-beta.10). It allows attackers to hijack accounts via pre-account hijacking during magic-link or email-OTP sign-in when open email/password registration is enabled. The attacker registers an account with the victim's email and a chosen password, leaving it unverified. When the victim later signs in via magic-link or email-OTP, the account becomes verified without removing the attacker's password or sessions, allowing persistent access.

Impact Analysis

If you use a vulnerable version of better-auth with open email/password registration enabled, an attacker could gain persistent access to your account. They could register your email with their password, then take over your account when you use magic-link or email-OTP sign-in. This could lead to unauthorized access to your data, actions performed on your behalf, or complete account compromise.

Mitigation Strategies

Immediately upgrade better-auth to version 1.6.22 or later, or 1.7.0-beta.10 or later if using pre-release versions. Disable open email/password registration if not required to prevent attackers from registering accounts with victim email addresses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67327. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart