Junglewise Threat Intelligence

CVE-2026-67337: better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers wi

CVE-2026-67337 · Severity: medium · CVSS 6.5 · Published 2026-08-01

Technologies: better-auth (npm). Vendors: npm, Better-Auth.

Executive brief

Better Auth is an authentication framework that supports two-factor authentication (2FA) to protect user accounts. When session caching is enabled, a critical flaw allows attackers to bypass 2FA by using a cached session from before the second authentication factor is verified, gaining full access to protected application routes without completing the second factor.

Technical details

This is an authentication bypass vulnerability (CWE-288) in Better Auth's session management. When both 2FA and session.cookieCache are enabled, the library caches a session as valid after the initial sign-in but before 2FA verification is complete. Subsequent session lookups return the cached session without re-evaluating the 2FA requirement, allowing an attacker with valid primary credentials to access authenticated routes without completing 2FA. The vulnerability affects version 1.4.5 and earlier; it was fixed in version 1.4.9. The attack requires valid primary credentials and does not require user interaction once primary authentication is obtained. As a temporary mitigation, disabling session.cookieCache when using 2FA can prevent exploitation.

Affected products

  • Better Auth better-auth < 1.4.9

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: patched: Fix released in version 1.4.9

References

Related threats