CVE-2026-67332 MEDIUM

CVE-2026-67332: @better-auth/oauth-provider before 1.7.0-beta.4 Authorization Bypass

Vendor Better-Auth
Product oauth-provider
Weakness CWE-285
Published August 1, 2026
Last update August 1, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing intended authorization boundaries.

Key dates

02Disclosure timeline

August 1, 2026 CVE published

Related vulnerabilities

04Related CVE