{"id":"CVE-2026-67327","aliases":["GHSA-qq9h-g4jm-xgf3"],"url":"https://o3.security/vulnerability/CVE-2026-67327","summary":"better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP","details":"better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address and an attacker-chosen password; the account remains unverified. When the legitimate owner later signs in via the magic-link or email-OTP passwordless flow, the account is marked verified without removing the pre-existing password or revoking existing sessions, so the attacker's password remains valid, granting persistent access to the victim's account. Fixed in 1.6.22 and 1.7.0-beta.10.","published":"2026-08-01T12:22:17.753Z","modified":"2026-08-12T03:51:30.643606544Z","cvss":null,"epss":{"score":0.00231,"percentile":0.13802,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"better-auth","fixedVersion":"1.6.22"},{"ecosystem":"npm","name":"better-auth","fixedVersion":"1.7.0-beta.10"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67327.json"},{"type":"ADVISORY","url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-qq9h-g4jm-xgf3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67327"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/better-auth-before-account-takeover-via-magic-link-email-otp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.643606544Z"}}