A high-severity vulnerability, CVE-2026-53515 with a CVSS score of 7.1, affects the better-auth/sso package in versions greater than or equal to 1.2.10 and less than 1.6.11. This flaw allows an unauthorized registration of SSO providers due to an authorization mismatch for the same resource, enabling a low-privilege organization member to create a provider record they would not be allowed to view, update, or delete through companion provider-management endpoints. The attack vector is network-based and requires no specific conditions or attacker capabilities other than the ability to register an SSO provider in the affected organization. This vulnerability has a high business impact as it allows unauthorized access to sensitive data and enables malicious actors to create new users with admin roles in the target organization, potentially leading to unauthorized provider configuration within an organization tenant, unauthorized organization membership creation, and admin creation when configured.
We recommend you to update @better-auth/sso to version 1.6.11.[/subscribe_to_unlock_form]
A high-severity vulnerability, CVE-2026-53515 with a CVSS score of 7.1, affects the better-auth/sso package in versions greater than or equal to 1.2.10 and less than 1.6.11. This flaw allows an unauthorized registration of SSO providers due to an authorization mismatch for the same resource, enabling a low-privilege organization member to create a provider record they would not be allowed to view, update, or delete through companion provider-management endpoints. The attack vector is network-based and requires no specific conditions or attacker capabilities other than the ability to register an SSO provider in the affected organization. This vulnerability has a high business impact as it allows unauthorized access to sensitive data and enables malicious actors to create new users with admin roles in the target organization, potentially leading to unauthorized provider configuration within an organization tenant, unauthorized organization membership creation, and admin creation when configured.
We recommend you to update @better-auth/sso to version 1.6.11.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]