CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67332

mediumCVSS 6.4covered by 1 sourcefirst seen 2026-08-01
@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing intended authorization boundaries.

⚡ Watch CVE-2026-67332

Get an email if CVE-2026-67332 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67332

CVE.org record

Embed the live status

CVE-2026-67332 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67332 status](https://www.csirts.com/badge/CVE-2026-67332)](https://www.csirts.com/cve/CVE-2026-67332)