Executive brief
A vulnerability in the Better Auth SSO plugin allows regular organization members to register their own Single Sign-On (SSO) providers without administrative approval. This could allow an attacker to link a malicious identity provider to an organization, potentially leading to unauthorized account creation or administrative access within that organization. This affects applications using both the SSO and Organization plugins where user-driven registration is enabled.
Technical details
The vulnerability exists in the 'POST /sso/register' endpoint of the '@better-auth/sso' package. While other management endpoints (list, update, delete) correctly enforce 'owner' or 'admin' roles via the 'isOrgAdmin' check, the registration path only verifies that the user is a member of the organization without checking their specific role. An attacker with low-privilege 'member' access can register a malicious OIDC or SAML provider. If organization provisioning is enabled, this can be used to inject new users into the organization, potentially with administrative privileges if 'defaultRole' is misconfigured. The issue is fixed in version 1.6.11 by implementing a mandatory role check during registration.
Affected products
- better-auth @better-auth/sso >= 1.2.10, < 1.6.11
Timeline
- 2026-04-12: disclosed: Public issue #9133 raised
- 2026-07-15: advisory: NVD publication date
- 2026-07-20: patched: GitHub Advisory published and fix confirmed in v1.6.11