Junglewise Threat Intelligence

CVE-2026-67329: @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organizatio

CVE-2026-67329 · Severity: high · CVSS 7.1 · Published 2026-08-01

Vendors: Better-Auth.

Executive brief

The @better-auth/stripe plugin, which manages subscription billing for organizations, contains a flaw that allows an authenticated user who belongs to multiple organizations to perform billing actions (cancel subscriptions, change plans, restore service, or access billing portals) on organizations they should not manage. An attacker with membership in multiple organizations can view sensitive billing details including payment methods, invoices, and subscription status for other organizations they belong to.

Technical details

The vulnerability is an incorrect authorization check (CWE-863) and authorization bypass through user-controlled keys (CWE-639) in the organization subscription action handlers. The plugin validates the organization ID from the request query string in middleware, but the actual action handler reads the organization ID only from the request body and falls back to the user's active organization from session when the body is empty. When an authenticated user sends a request with a managed organization in the query string but no ID in the body, the middleware approves the queried organization while the handler operates on the active organization, causing a mismatch. The target organization is always one the user belongs to, but the user may not have billing management rights. Attack requires authentication, valid membership in multiple organizations, and the target application to have both subscription.enabled and organization.enabled settings active. Patches are available in @better-auth/stripe 1.6.21 and 1.7.0-beta.10 or later.

Affected products

  • better-auth Stripe >=1.4.11, <1.6.21; >=1.7.0-beta.0, <1.7.0-beta.10

Timeline

  • 2026-07-24: disclosed
  • 2026-06-25: patched: Fix committed; patches released as 1.6.21 and 1.7.0-beta.10

References