vulns.co
/
GKData.io MCP

Better Auth · 1 min read

Better Auth: incoming identity proof does not validate existing credentials

CVE-2026-53516 concerns implicit linking to an unverified local account. Provider-side email verification was allowed to confer legitimacy on previously stored local credentials. The resulting merged identity could retain an unauthorized password-based login even when ordinary email verification was required.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial reasoning: linking combines authorities, so prove ownership on both sides before merging credentials. Requiring verification only after the merge cannot establish who created the earlier password. Release 1.6.11 corroborates a verified-local-email gate; the advisory also identifies 1.7.0-beta.4 as patched. Disabling implicit linking is a documented interim control.

Before reading

  • OAuth identity-provider claims and local account-linking concepts

Context and limits

  • Exposure requires email/password sign-in, OAuth or SSO, implicit linking, and an existing unverified local account before the legitimate federated sign-in. Impact is account access, not compromise of the identity provider.
  • The advisory lists stable versions below 1.6.11 and 1.7.0-beta.0 through beta.3. Its deprecated compatibility opt-out restores weaker linking behavior.
  • gustavovalverde published the advisory; avrmeduard is credited as reporter. Release notes show May 12 without an explicit year in retrieved text; exact patch date is left unestablished.
  • Maintainer disclosure, not a peer-reviewed paper, award-backed report, or evidence of production exploitation.

Sources and provenance

  1. better-auth: OAuth sign-in can link to an account an attacker registered in advance Better Auth · reviewed 2026-10-03
  2. Release v1.6.11 Better Auth · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software