PatchSiren cyber security CVE debrief
CVE-2026-67332 better-auth CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:03.973Z and has not been modified since then. The vulnerability affects @better-auth/oauth-provider before 1.7.0-beta.4, allowing clients to request tokens for unrelated resources. This can be exploited by attackers to bypass intended authorization boundaries and obtain access tokens for unauthorized resources. Organizations using @better-auth/oauth-provider before 1.7.0-beta.4 should prioritize upgrading to a patched version to prevent potential authorization bypass attacks. The debrief provides an executive overview of the vulnerability, its likely operational impact, and source-confidence limits. Evidence notes provide source grounding, evidence limits, known and unknown affected scope, and what defenders should verify.
- Vendor
- better-auth
- Product
- oauth-provider
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
Organizations using @better-auth/oauth-provider before 1.7.0-beta.4 should be aware of this vulnerability and take steps to mitigate it. This includes upgrading to a patched version and reviewing authorization configurations to prevent potential authorization bypass attacks. Affected operators, platforms, and security teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. Vulnerability management and security teams should prioritize upgrading to a patched version and monitor for potential unauthorized access attempts. Asset inventory and platform teams should review and update authorization configurations to ensure proper binding of access-token audience to authorization grants. Monitoring and detection teams should check relevant logs for exposed assets that need extra review. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Rollback/change windows and source tracking should be considered for exposed systems. The debrief provides an executive overview of the vulnerability, its likely operational impact, and source-confidence limits. The technical summary provides affected product context, defensive impact, and source-grounded technical framing without unsupported root-cause or exploit claims. Evidence notes provide source grounding, evidence limits, known and unknown affected scope, and what defenders should verify. Recommended actions provide distinct safe defensive actions until the target count is met. The defensive priority is high for organizations using @better-auth/oauth-provider before 1.7.0-beta.4. The CVE record was published on 2026-08-01T13:17:03.973Z and has not been modified since then. The NVD detail and CVE record provide additional information about the vulnerability. The source item URL provides additional context. The official CVE record and NVD detail provide official guidance on affected scope, severity, and vendor guidance. The source reference provides additional information about the vulnerability. The @
Technical summary
The @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. This vulnerability can be exploited by attackers to bypass intended authorization boundaries and obtain access tokens for unauthorized resources. Affected organizations should prioritize upgrading to a patched version to prevent potential authorization bypass attacks. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM.
Defensive priority
Organizations using @better-auth/oauth-provider before 1.7.0-beta.4 should prioritize upgrading to a patched version to prevent potential authorization bypass attacks.
Recommended defensive actions
- Upgrade to @better-auth/oauth-provider version 1.7.0-beta.4 or later
- Review and update authorization configurations to ensure proper binding of access-token audience to authorization grants
- Monitor for potential unauthorized access attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE description indicates that @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. However, detailed information about the vulnerability and its impact is limited in the provided source corpus. Further verification is needed to understand the full scope of the vulnerability and its potential impact on affected systems. Defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:03.973Z and has not been modified since then.