THREAT OPS › Threat News › [NVD] CVE-2026-67335 (MEDIUM 5.3) — better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions
[NVD] CVE-2026-67335 (MEDIUM 5.3) — better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions
CVE-2026-67335 CVSS: 5.3 MEDIUM Published: 2026-08-01T13:17:04.403
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persis
Indicators of compromise
- CVE-2026-67335cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67335