{"api_version":"1","generated_at":"2026-07-24T19:44:29+00:00","cve":"CVE-2026-45337","urls":{"html":"https://cve.report/CVE-2026-45337","api":"https://cve.report/api/cve/CVE-2026-45337.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-45337","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-45337"},"summary":{"title":"Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending","description":"Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim the row and POST /device/approve and POST /device/deny short-circuit when userId is unset, allowing an authenticated attacker who learns a valid user_code to bind the polling device to the attacker's account or deny the legitimate flow. This issue is fixed in version 1.6.11.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-07-15 18:16:45","updated_at":"2026-07-21 04:21:25"},"problem_types":["CWE-285","CWE-345","CWE-285 CWE-285: Improper Authorization","CWE-345 CWE-345: Insufficient Verification of Data Authenticity"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"7.6","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.6","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","version":"3.1"}}],"references":[{"url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-cq3f-vc6p-68fh","name":"https://github.com/better-auth/better-auth/security/advisories/GHSA-cq3f-vc6p-68fh","refsource":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/better-auth/better-auth/pull/9573","name":"https://github.com/better-auth/better-auth/pull/9573","refsource":"security-advisories@github.com","tags":["Issue Tracking","Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/better-auth/better-auth/commit/99a254a79b59d5a3f5ca2123260118cddb5beed7","name":"https://github.com/better-auth/better-auth/commit/99a254a79b59d5a3f5ca2123260118cddb5beed7","refsource":"security-advisories@github.com","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/better-auth/better-auth/releases/tag/v1.6.11","name":"https://github.com/better-auth/better-auth/releases/tag/v1.6.11","refsource":"security-advisories@github.com","tags":["Release Notes"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-45337","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45337","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"better-auth","product":"better-auth","version":"affected >= 1.6.0, < 1.6.11","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"45337","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"better-auth","cpe5":"better_auth","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"45337","cve":"CVE-2026-45337","epss":"0.001400000","percentile":"0.037980000","score_date":"2026-07-21","updated_at":"2026-07-22 00:11:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-45337","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-07-15T18:02:43.206553Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-15T18:02:58.506Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"better-auth","vendor":"better-auth","versions":[{"status":"affected","version":">= 1.6.0, < 1.6.11"}]}],"descriptions":[{"lang":"en","value":"Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim the row and POST /device/approve and POST /device/deny short-circuit when userId is unset, allowing an authenticated attacker who learns a valid user_code to bind the polling device to the attacker's account or deny the legitimate flow. This issue is fixed in version 1.6.11."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-15T17:31:44.983Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/better-auth/better-auth/security/advisories/GHSA-cq3f-vc6p-68fh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-cq3f-vc6p-68fh"},{"name":"https://github.com/better-auth/better-auth/pull/9573","tags":["x_refsource_MISC"],"url":"https://github.com/better-auth/better-auth/pull/9573"},{"name":"https://github.com/better-auth/better-auth/commit/99a254a79b59d5a3f5ca2123260118cddb5beed7","tags":["x_refsource_MISC"],"url":"https://github.com/better-auth/better-auth/commit/99a254a79b59d5a3f5ca2123260118cddb5beed7"},{"name":"https://github.com/better-auth/better-auth/releases/tag/v1.6.11","tags":["x_refsource_MISC"],"url":"https://github.com/better-auth/better-auth/releases/tag/v1.6.11"}],"source":{"advisory":"GHSA-cq3f-vc6p-68fh","discovery":"UNKNOWN"},"title":"Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-45337","datePublished":"2026-07-15T17:31:44.983Z","dateReserved":"2026-05-11T21:40:08.176Z","dateUpdated":"2026-07-15T18:02:58.506Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-15 18:16:45","lastModifiedDate":"2026-07-21 04:21:25","problem_types":["CWE-285","CWE-345","CWE-285 CWE-285: Improper Authorization","CWE-345 CWE-345: Insufficient Verification of Data Authenticity"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-15T18:02:43.206553Z","id":"CVE-2026-45337","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:better-auth:better_auth:*:*:*:*:*:node.js:*:*","versionStartIncluding":"1.6.0","versionEndExcluding":"1.6.11","matchCriteriaId":"DCC78752-9FCD-4276-AC25-AE441D750A69"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"45337","Ordinal":"1","Title":"Better Auth: Device authorization approve and deny accept any au","CVE":"CVE-2026-45337","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"45337","Ordinal":"1","NoteData":"Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim the row and POST /device/approve and POST /device/deny short-circuit when userId is unset, allowing an authenticated attacker who learns a valid user_code to bind the polling device to the attacker's account or deny the legitimate flow. This issue is fixed in version 1.6.11.","Type":"Description","Title":"Better Auth: Device authorization approve and deny accept any au"}]}}}