Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 01 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Better-auth better Auth
|
|
| Vendors & Products |
Better-auth better Auth
|
Sat, 01 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching. | |
| Title | better-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieCache | |
| First Time appeared |
Better-auth
Better-auth better-auth\/oauth-provider |
|
| Weaknesses | CWE-288 | |
| CPEs | cpe:2.3:a:better-auth:better-auth\/oauth-provider:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Better-auth
Better-auth better-auth\/oauth-provider |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-01T12:22:18.034Z
Reserved: 2026-07-29T13:07:47.016Z
Link: CVE-2026-67337
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-01T14:30:05Z
-
CWE-288
Authentication Bypass Using an Alternate Path or Channel