Vulnerability Description
Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach a new SSO provider to that organization because registerSSOProvider checks only for a membership row and does not require an owner or admin role, allowing attacker-controlled OIDC or SAML providers to drive /sso/callback/{providerId} organization provisioning. This issue is fixed in version 1.6.11.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Better-Auth | Better-Auth\/Sso | < 1.6.11 |
| Better-Auth | Better Auth | >= 1.2.10, < 1.6.11 |
Related Weaknesses (CWE)
References
- https://github.com/better-auth/better-auth/commit/86765f1597378f5c3deed1b80ca91fPatch
- https://github.com/better-auth/better-auth/pull/9220Issue TrackingPatch
- https://github.com/better-auth/better-auth/releases/tag/v1.6.11Release Notes
- https://github.com/better-auth/better-auth/security/advisories/GHSA-gv74-j8m3-fgMitigationVendor Advisory
FAQ
What is CVE-2026-53515?
CVE-2026-53515 is a vulnerability with a CVSS score of 7.1 (HIGH). Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach a new...
How severe is CVE-2026-53515?
CVE-2026-53515 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53515?
Check the references section above for vendor advisories and patch information. Affected products include: Better-Auth Better-Auth\/Sso, Better-Auth Better Auth.