CVE-2026-67334
Received Received - Intake

better-auth Session Token Reuse After User Deletion

Vulnerability report for CVE-2026-67334, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: VulnCheck

Description

better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
better-auth better-auth to 1.6.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

better-auth versions before 1.6.11 have a flaw where cached sessions are not deleted when users are removed via admin, anonymous, or SCIM endpoints if secondaryStorage is enabled and storeSessionInDatabase is false. This allows attackers to reuse deleted user session tokens for up to seven days after account deletion.

Impact Analysis

Attackers could maintain unauthorized access to systems for up to seven days after a user account is deleted. This could lead to data breaches, unauthorized actions, or prolonged access to sensitive resources.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR and HIPAA by failing to properly terminate user sessions, potentially leading to unauthorized data access. Compliance may be compromised due to insufficient session management.

Mitigation Strategies

Upgrade better-auth to version 1.6.11 or later to fix the session deletion issue. If using secondaryStorage with storeSessionInDatabase set to false, verify that cached sessions are properly invalidated upon user removal.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67334. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart