CVE-2026-67337

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 13:17

Updated : 2026-09-08 20:34


NVD link : CVE-2026-67337

Mitre link : CVE-2026-67337

CVE.ORG link : CVE-2026-67337


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel