THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67329 (HIGH 7.1) — @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference call

[NVD] CVE-2026-67329 (HIGH 7.1) — @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference call

mednvdPublished 2026-08-01

CVE-2026-67329 CVSS: 7.1 HIGH Published: 2026-08-01T13:17:03.523

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the organization ID only f

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67329