
CVE-2026-67337 better-auth 2FA bypass could let attackers with valid primary credentials access protected routes without completing MFA when session cookie caching is enabled Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-01/TIER_2_CVE-2026-67337.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement
Post summary
The text announces CVE‑2026‑67337, a 2FA bypass when session cookie caching is enabled, providing the vulnerability details but no proof of concept, exploit, patch, or evidence of active exploitation.
