THREAT OPS › Threat News › [NVD] CVE-2026-67329 (HIGH 7.1) — @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference call
[NVD] CVE-2026-67329 (HIGH 7.1) — @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference call
CVE-2026-67329 CVSS: 7.1 HIGH Published: 2026-08-01T13:17:03.523
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the organization ID only f
Indicators of compromise
- CVE-2026-67329cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67329