CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67329

highCVSS 7.1covered by 1 sourcefirst seen 2026-08-01
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the organization ID only from the request body and falls back to the caller's active organization from their session. When these differ, an authenticated member of multiple organizations can perform subscription actions (cancel, change plan, restore, billing portal access) against an organization they belong to but should not manage, and can access another organization's billing details including payment methods, invoices, and subscription state.

⚡ Watch CVE-2026-67329

Get an email if CVE-2026-67329 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67329

CVE.org record

Embed the live status

CVE-2026-67329 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67329 status](https://www.csirts.com/badge/CVE-2026-67329)](https://www.csirts.com/cve/CVE-2026-67329)