CVE-2026-53516 – Better Auth

CVSS 8.3 IMPORTANT Critical - Same Day Deployment

“Authentication is only as strong as its weakest trust decision.”

Better Auth version 1.6.11 addresses six vulnerabilities affecting authentication, authorization, OAuth, SSO, device authorization, and organization invitation workflows. The update fixes a critical server-side request forgery (SSRF) vulnerability along with multiple high-severity flaws that could enable unauthorized account linking, privilege escalation, security control bypass, refresh token reuse through race conditions, and unauthorized management of SSO providers or organization invitations.

CVE-2026-53513 has a CVSS score of 9.6, Critical severity. CVE-2026-53516 has a CVSS score of 8.3, High severity. CVE-2026-53517 has a CVSS score of 8.1, High severity. CVE-2026-45337 has a CVSS score of 7.6, High severity. CVE-2026-53514 has a CVSS score of 7.7, High severity. CVE-2026-53515 has a CVSS score of 7.1, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Key Details

Affected Product
Better-auth Better Auth
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-287
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.