PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-67336 better-auth CVE debrief

CVE-2026-67336 is a critical vulnerability in better-auth versions before 1.6.11, affecting the oidcProvider and mcp plugins. The vulnerability involves insecure cryptographic defaults, advertising the none algorithm, and accepting plain PKCE by default. This allows attackers to exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used. Affected deployments should prioritize upgrading to a secure version to prevent potential attacks. Review of cryptographic settings for oidcProvider and mcp plugins is also necessary. The CVE record was published on 2026-08-01T13:17:04.557Z and has not been modified since then. To verify, defenders should review the official CVE record and assess their exposure. The lack of detailed information may hinder thorough risk assessment and mitigation planning.

Vendor
better-auth
Product
Unknown
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

Developers and administrators using better-auth versions before 1.6.11 should be aware of the potential risks and take steps to mitigate them. This includes reviewing and adjusting cryptographic settings for oidcProvider and mcp plugins, monitoring for potential attacks exploiting algorithm negotiation, and prioritizing upgrades to secure versions. Security teams and vulnerability management teams should also be aware of the potential impact on their systems and plan accordingly. Operators of affected systems need to assess their exposure and implement compensating controls if necessary. Platform administrators should verify that their configurations are secure and consider additional monitoring for suspicious activity related to authentication and authorization processes. Vulnerability management teams should incorporate this information into their risk assessments and prioritize remediation efforts based on the severity of the vulnerability and the potential impact on their systems. Security teams should review the official CVE record and assess their exposure to ensure that they are adequately prepared to respond to potential attacks. Asset owners should verify that their assets are not vulnerable and implement compensating controls if necessary. Incident response teams should be prepared to respond to potential attacks exploiting this vulnerability. Compliance teams should review their organization's compliance with relevant regulations and standards related to cryptographic practices and authentication mechanisms. Business stakeholders should be aware of the potential risks and impacts on business operations and make informed decisions about remediation and mitigation strategies. IT management should prioritize remediation efforts based on the severity of the vulnerability and the potential impact on business operations. External stakeholders, such as customers and partners, may also be affected if they use or interact with systems that rely on better-auth versions before 1.6.11. They should be informed about potential risks and take necessary precautions to protect their systems and data. Suppliers and vendors that provide products or services that rely on

Technical summary

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins, advertising the none algorithm and accepting plain PKCE by default. This allows attackers to exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used. Affected deployments should prioritize upgrading to a secure version to prevent potential attacks. Review of cryptographic settings for oidcProvider and mcp plugins is also necessary.

Defensive priority

Organizations using better-auth versions before 1.6.11 should prioritize upgrading to a secure version to prevent potential attacks.

Recommended defensive actions

  • Upgrade to better-auth version 1.6.11 or later
  • Review and adjust cryptographic settings for oidcProvider and mcp plugins
  • Monitor for potential attacks exploiting algorithm negotiation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE description notes that better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins. However, detailed information about the vulnerability and its impact is limited in the provided source corpus. To verify, defenders should review the official CVE record and assess their exposure. The lack of detailed information may hinder thorough risk assessment and mitigation planning.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:04.557Z and has not been modified since then.