CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67336

highCVSS 8.7covered by 1 sourcefirst seen 2026-08-01
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.

⚡ Watch CVE-2026-67336

Get an email if CVE-2026-67336 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67336

CVE.org record

Embed the live status

CVE-2026-67336 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67336 status](https://www.csirts.com/badge/CVE-2026-67336)](https://www.csirts.com/cve/CVE-2026-67336)