Medium severity5.3NVD Advisory· Published Aug 1, 2026· Updated Sep 8, 2026
CVE-2026-67335
CVE-2026-67335
Description
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persistently link attacker accounts to victim profiles.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.6.2
Patches
Vulnerability mechanics
References
2News mentions
1- Better Auth: 17 Vulnerabilities Disclosed Together, Including Critical Authorization Bypass FlawsVypr Intelligence · Aug 2, 2026