CVE-2025-71400

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys.
Configurations

No configuration.

History

02 Aug 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-08-02 13:16

Updated : 2026-08-03 17:16


NVD link : CVE-2025-71400

Mitre link : CVE-2025-71400

CVE.ORG link : CVE-2025-71400


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key