cvedb.io
CVE-2026-67332
MEDIUM · CVSS 6.4
EPSS exploitation probability: 0%
Published 2026-08-01T13:17:03.973 · Last modified 2026-08-01T13:17:03.973

Summary

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing intended authorization boundaries.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.