MEDIUMVulnerability

CVE-2026-67337

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00269
cve_id
CVE-2026-67337
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-01T13:17:04.693
last_modified
2026-09-08T20:34:34.997
epss_percentile
0.18817

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass Using an Alternate Path or Channel

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67337 — Ninja Signal Threat Intelligence | Ninja Signal