CVE-2026-67334
⚪ Do wiadomości
Błąd w better-auth pozwala na ponowne użycie tokenów sesji usuniętych użytkowników przez siedem dni.
CVSS
3.8
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-08-01 13:17:04 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-03 19:16:52 UTC |
Referencje
- https://github.com/better-auth/better-auth/security/advisories/GHSA-2vg6-77g8-24mp (disclosure@vulncheck.com)
- https://www.vulncheck.com/advisories/better-auth-stale-sessions-persist-after-user-deletion (disclosure@vulncheck.com)