Low severity3.8NVD Advisory· Published Aug 1, 2026· Updated Sep 8, 2026
CVE-2026-67334
CVE-2026-67334
Description
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.6.11
Patches
Vulnerability mechanics
References
2News mentions
1- Better Auth: 17 Vulnerabilities Disclosed Together, Including Critical Authorization Bypass FlawsVypr Intelligence · Aug 2, 2026