CVE-2026-67336Disclosure

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-01); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-01: 2Mentions · 2026-08-03: 2Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-01: 2Technical Details · 2026-08-03: 108-0108-03
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-012
Disclosure2
2026-08-032
General1Patch1
Full discourse4 posts
  • Mohi@disismohi
    Patch

    If your auth stack uses better-auth < 1.6.11, you're shipping two critical vulns by default. CVE-2026-67336, CVSS 8.7. Here's what breaks and how to fix it Monday.

    Post summary

    A warning that the better-auth library <1.6.11 contains a critical CVE-2026-67336 (CVSS 8.7), with a fix expected next Monday.

    1000056
    73 followersView on X
  • Mohi@disismohi
    General

    Insecure defaults kill platforms. If your auth library ships with 'none' algorithm support, you're one negotiation away from unsigned everything. source: https://nvd.nist.gov/vuln/detail/CVE-2026-67336

    Post summary

    The message notes that CVE‑2026‑67336 allows attack via insecure default support of the "none" algorithm, but provides no further technical or actionable details.

    0000031
    73 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-67336 better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE… https://www.cve.org/CVERecord?id=CVE-2026-67336 ----- Traducción: CVE-2026-67336 las… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑67336, outlining insecure crypto defaults in certain plugins, but provides no PoC, exploit code, or patch details.

    0000036
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-67336 better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE… https://www.cve.org/CVERecord?id=CVE-2026-67336

    Post summary

    The announcement highlights insecure cryptographic defaults in better-auth prior to 1.6.11—advertising the 'none' algorithm and accepting plain PKCE—but provides no PoC, exploit, or mitigation information.

    00000764
    57.9K followersView on X

Explore more