CVE-2026-53512Disclosure(better-auth / better_auth)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch better-auth better_auth systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without verifying the confidential client's client_secret, allowing an attacker with a valid refresh_token to mint access tokens and rotated refresh tokens through /api/auth/oauth2/token or /api/auth/mcp/token. The @better-auth/oauth-provider package is not affected. This issue is fixed in version 1.6.11.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306CWE-345CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • better_auth

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
better_auth

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-15: 1PoC Mentioned / Linked · 2026-07-15: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-0807-15
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-07-151
PoC1
Full discourse2 posts
  • Aretiq.AI@AretiqAI
    PoC

    ARETIQ Daily Vulnerability Bulletin — July 15, 2026 🔴 CRITICAL: CVE-2026-56699 (wazuh/wazuh) AAS 13.1 🔴 CRITICAL: CVE-2026-53512 (better-auth/better-auth) AAS 12.7 — PoC available 25 vulnerabilities — CRITICAL: 2, HIGH: 23 Full bulletin: https://aretiq.ai/bulletins/2026-07-15/

    Post summary

    The bulletin lists two critical CVEs, noting a PoC exists for one, but does not provide exploitation details, patches, or technical depth.

    00080810
    227 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - OAuth refresh_token client authentication bypass in better-auth OIDC/MCP plugins (CVE-2026-53512) In better-auth’s legacy oidcProvider and mcp plugins, the OAuth 2.0 token endpoint fails to authenticate confidential clients during the refresh_token grant, allowing token refresh without validating the client_secret. The root cause is improper authentication / missing secret verification (broken client authentication) combined with flawed Basic auth parsing and overly permissive CORS on the mcp token endpoint. An attacker who obtains a valid refresh_token and knows the public client_id can hit the token endpoint and repeatedly mint fresh access tokens and rotated refresh tokens until the token is revoked. Impact includes sustained unauthorized API access and session persistence, enabling account takeover-style access, data exposure, and long-lived compromise via continuous token renewal. 👉 Affected: better-auth legacy oidcProvider and mcp plugins < 1.6.11 | Upgrade to 1.6.11

    Post summary

    The post discloses CVE-2026-53512, explains an OAuth refresh_token authentication bypass, details its impact, and advises upgrading to version 1.6.11.

    0000091
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbetter-authbetter_auth-node.js-

Explore more