HIGHVulnerability

CVE-2026-67336

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.

Properties

severity
HIGH
score
8.7
epss_score
0.00159
cve_id
CVE-2026-67336
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
published_at
2026-08-01T13:17:04.557
last_modified
2026-09-08T20:34:34.997
epss_percentile
0.05336

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Use of a Broken or Risky Cryptographic Algorithm

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67336 — Ninja Signal Threat Intelligence | Ninja Signal