Junglewise Threat Intelligence

Better Auth account takeover via pre-account hijacking in magic-link and email-OTP

Severity: high · CVSS 8.3 · Published 2026-07-24

Vendors: Better-Auth.

Executive brief

A vulnerability in the Better Auth authentication library allows attackers to hijack user accounts through a "pre-account" attack. An attacker can register an account using a victim's email address and their own password; when the legitimate owner later signs in using a secure "magic link" or one-time password, the attacker's previously set password remains active. This allows the attacker to maintain persistent access to the account, potentially leading to data theft or total account lockout.

Technical details

Better Auth versions prior to 1.6.22 (and certain 1.7 betas) fail to revoke unverified credentials when an account is adopted via a passwordless flow. In a pre-account hijacking scenario, an attacker uses open registration to create an unverified account for a victim's email with a known password. When the victim later authenticates via the magic-link or email-OTP plugin, the system marks the account as verified but fails to delete the attacker-controlled password or revoke existing sessions. This allows the attacker to maintain concurrent access via the password credential. The fix introduces a helper that removes unproven credentials and revokes sessions during the verification step of passwordless flows.

Affected products

  • better-auth better-auth >= 1.1.3, < 1.6.22; >= 1.7.0-beta.0, < 1.7.0-beta.10

Timeline

  • 2026-06-26: disclosed: Initial disclosure and pull request created
  • 2026-06-26: patched: Fix merged into main branch
  • 2026-07-24: advisory: GitHub Advisory published

References