7.1
CVE-2026-53515
- EPSS 0.24%
- Veröffentlicht 15.07.2026 17:27:00
- Zuletzt bearbeitet 21.07.2026 15:38:36
- CVE-Watchlists
- Unerledigt
Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso
Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach a new SSO provider to that organization because registerSSOProvider checks only for a membership row and does not require an owner or admin role, allowing attacker-controlled OIDC or SAML providers to drive /sso/callback/{providerId} organization provisioning. This issue is fixed in version 1.6.11.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Better-auth ≫ Better-auth/sso SwPlatformnode.js Version < 1.6.11
Better-auth ≫ Better Auth SwPlatformnode.js Version >= 1.2.10 < 1.6.11
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.15 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/better-auth/better-auth/releases/tag/v1.6.11
https://github.com/better-auth/better-auth/security/advisories/GHSA-gv74-j8m3-fg5f
https://github.com/better-auth/better-auth/pull/9220
https://github.com/better-auth/better-auth/commit/86765f1597378f5c3deed1b80ca91faac0a6bf00