MEDIUMVulnerability

CVE-2026-67332

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing intended authorization boundaries.

Properties

severity
MEDIUM
score
6.4
epss_score
0.00162
cve_id
CVE-2026-67332
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
published_at
2026-08-01T13:17:03.973
last_modified
2026-09-08T20:34:34.997
epss_percentile
0.05724

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67332 — Ninja Signal Threat Intelligence | Ninja Signal