GHSA-8pwm-pjg9-4h92HighCVSS 6.5

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when...

Published
August 1, 2026
Last Modified
August 1, 2026

🔗 CVE IDs covered (1)

📋 Description

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching.

🔗 References (4)