
CVE-2026-67328 @better-auth/sso Potential account takeover through provider registration, orphaned accounts, unbound SAML assertions or reflected XSS in affected configurations Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-01/TIER_2_CVE-2026-67328.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement
Post summary
The report highlights potential account takeover risks in better-auth/sso owing to orphaned accounts, unbound SAML assertions, and reflected XSS, but does not provide PoC, exploit details, or patch information.
