better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching.
References
Configurations
No configuration.
History
01 Aug 2026, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-01 13:17
Updated : 2026-08-01 13:17
NVD link : CVE-2026-67337
Mitre link : CVE-2026-67337
CVE.ORG link : CVE-2026-67337
JSON object : View
Products Affected
No product.
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
