← Terug naar overzicht

CVE-2026-80192 affects @better-auth/sso before versions 1.6.27, 1.4.8, and 1.7.0-rc.5, exposing two domain-ownership vulnerabilities. When domain verification is disabled, an authenticated organization owner or administrator can register an SSO provider for an arbitrary domain, causing users with matching email domains to be automatically added to the attacker's organization. When domain verification is enabled, a race condition between the verify-domain and update-provider endpoints allows a completed DNS proof to be applied to a different domain than intended. This race condition, combined with implicit account linking, can allow an attacker to link a controlled identity provider to an existing user account. Exploitation requires the SSO plugin to be active and, for the organization assignment attack path, the organization plugin must also be enabled. The vulnerability represents a significant authentication bypass and unauthorized access risk in affected deployments.

Affected products

  • '@better-auth/sso

Related CVE's

  • CVE-2026-80192

Categories

  • Identity & Access
  • Supply Chain & Dependencies
  • Web Technologies