CVE-2026-80192
Received Received - Intake

Authentication Bypass in Better Auth SSO Plugin

Vulnerability report for CVE-2026-80192, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: VulnCheck

Description

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization owner/administrator to register an SSO provider for an arbitrary domain and have users with matching email domains added to the attacker's organization with default member permissions. When domain verification is enabled, a race condition between the verify-domain and update-provider endpoints can apply completed DNS proof to a different domain; combined with implicit account linking, this can link an attacker-controlled identity provider to an existing user account. Exploitation requires the SSO plugin (and, for the org-assignment path, the organization plugin) with the relevant configuration enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
better-auth sso to 1.6.27|end_excluding=1.4.8 (exc)
better-auth sso to 1.7.0-rc.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the @better-auth/sso package before versions 1.6.27, 1.4.8, and 1.7.0-rc.5. It involves two domain-ownership flaws that allow attackers to manipulate SSO provider registrations and user account associations. When domain verification is disabled, attackers can register SSO providers for arbitrary domains and add users with matching email domains to their organization. When domain verification is enabled, a race condition can link an attacker-controlled identity provider to an existing user account.

Impact Analysis

If you use the affected versions of @better-auth/sso with SSO or organization plugins enabled, an attacker could gain unauthorized access to your organization or link their identity provider to your user account. This could lead to data exposure, unauthorized actions, or account takeovers depending on the configuration.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating principles of data protection and access control required by GDPR and HIPAA. Organizations using the affected software may face compliance risks due to potential breaches of confidentiality and integrity.

Mitigation Strategies

Update @better-auth/sso to version 1.6.27 or later (or 1.4.8 for 1.4.x line or 1.7.0-rc.5 for 1.7 prerelease line) to address the domain-ownership flaws. Disable domain verification only if absolutely necessary and monitor for suspicious SSO provider registrations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80192. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart