CVE-2026-41427: Better Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clients

Published Apr 24, 2026
·
Updated

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation endpoints did not invoke the hook before persisting new clients. Deployments that configured clientPrivileges to restrict client registration were not actually restricted — any authenticated user could reach the create endpoints and register an OAuth client with attacker-chosen redirect URIs and metadata. This vulnerability is fixed in 1.6.5.

Affected Software

5 affected components
npm/better-auth<1.6.5
better-auth Better-auth\/oauth-provider Node.js>=1.4.9<1.6.5
better-auth Better-auth\/oauth-provider Node.js=1.4.8
better-auth Better-auth\/oauth-provider Node.js=1.4.8-beta7
better-auth Better-auth\/oauth-provider Node.js=1.7.0-beta0

Event History

Apr 24, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-41427?

CVE-2026-41427 is considered a high severity vulnerability due to the risk of unprivileged users registering OAuth clients.

2

How do I fix CVE-2026-41427?

To fix CVE-2026-41427, upgrade Better Auth to version 1.6.5 or later to ensure proper permissions for OAuth client registration.

3

What impact does CVE-2026-41427 have on my application?

CVE-2026-41427 allows unprivileged users to register OAuth clients, potentially compromising security and user data.

4

Is my application affected by CVE-2026-41427?

If your application uses Better Auth versions prior to 1.6.5 and allows OAuth client registration, it is affected by CVE-2026-41427.

5

What is Better Auth in relation to CVE-2026-41427?

Better Auth is an authentication and authorization library for TypeScript, which contains the vulnerability CVE-2026-41427 affecting OAuth client creation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203