๐Ÿ” CVE Alert

CVE-2026-67329

HIGH 7.1

@better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the organization ID only from the request body and falls back to the caller's active organization from their session. When these differ, an authenticated member of multiple organizations can perform subscription actions (cancel, change plan, restore, billing portal access) against an organization they belong to but should not manage, and can access another organization's billing details including payment methods, invoices, and subscription state.

CWE CWE-639
Vendor better-auth
Product stripe
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for better-auth stripe

Be the first to know when new high vulnerabilities affecting better-auth stripe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

better-auth / stripe
1.4.11 < 1.6.21
better-auth / stripe
1.7.0-beta.0 < 1.7.0-beta.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/better-auth/better-auth/security/advisories/GHSA-h3rm-78g3-j7cp vulncheck.com: https://www.vulncheck.com/advisories/better-auth-stripe-before-authorization-bypass-via-organization-subscription