PatchSiren cyber security CVE debrief
CVE-2026-67336 better-auth CVE debrief
CVE-2026-67336 is a critical vulnerability in better-auth versions before 1.6.11, affecting the oidcProvider and mcp plugins. The vulnerability involves insecure cryptographic defaults, advertising the none algorithm, and accepting plain PKCE by default. This allows attackers to exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used. Affected deployments should prioritize upgrading to a secure version to prevent potential attacks. Review of cryptographic settings for oidcProvider and mcp plugins is also necessary. The CVE record was published on 2026-08-01T13:17:04.557Z and has not been modified since then. To verify, defenders should review the official CVE record and assess their exposure. The lack of detailed information may hinder thorough risk assessment and mitigation planning.
- Vendor
- better-auth
- Product
- Unknown
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
Developers and administrators using better-auth versions before 1.6.11 should be aware of the potential risks and take steps to mitigate them. This includes reviewing and adjusting cryptographic settings for oidcProvider and mcp plugins, monitoring for potential attacks exploiting algorithm negotiation, and prioritizing upgrades to secure versions. Security teams and vulnerability management teams should also be aware of the potential impact on their systems and plan accordingly. Operators of affected systems need to assess their exposure and implement compensating controls if necessary. Platform administrators should verify that their configurations are secure and consider additional monitoring for suspicious activity related to authentication and authorization processes. Vulnerability management teams should incorporate this information into their risk assessments and prioritize remediation efforts based on the severity of the vulnerability and the potential impact on their systems. Security teams should review the official CVE record and assess their exposure to ensure that they are adequately prepared to respond to potential attacks. Asset owners should verify that their assets are not vulnerable and implement compensating controls if necessary. Incident response teams should be prepared to respond to potential attacks exploiting this vulnerability. Compliance teams should review their organization's compliance with relevant regulations and standards related to cryptographic practices and authentication mechanisms. Business stakeholders should be aware of the potential risks and impacts on business operations and make informed decisions about remediation and mitigation strategies. IT management should prioritize remediation efforts based on the severity of the vulnerability and the potential impact on business operations. External stakeholders, such as customers and partners, may also be affected if they use or interact with systems that rely on better-auth versions before 1.6.11. They should be informed about potential risks and take necessary precautions to protect their systems and data. Suppliers and vendors that provide products or services that rely on
Technical summary
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins, advertising the none algorithm and accepting plain PKCE by default. This allows attackers to exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used. Affected deployments should prioritize upgrading to a secure version to prevent potential attacks. Review of cryptographic settings for oidcProvider and mcp plugins is also necessary.
Defensive priority
Organizations using better-auth versions before 1.6.11 should prioritize upgrading to a secure version to prevent potential attacks.
Recommended defensive actions
- Upgrade to better-auth version 1.6.11 or later
- Review and adjust cryptographic settings for oidcProvider and mcp plugins
- Monitor for potential attacks exploiting algorithm negotiation
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE description notes that better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins. However, detailed information about the vulnerability and its impact is limited in the provided source corpus. To verify, defenders should review the official CVE record and assess their exposure. The lack of detailed information may hinder thorough risk assessment and mitigation planning.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:04.557Z and has not been modified since then.