CVE-2026-53516Better-auth · Better_auth
Vulnerability data via NVD (ingested)
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user row's emailVerified field to also be true, allowing an attacker who pre-registers a victim email through /sign-up/email to bind the victim's OAuth identity to the attacker's account. The same primitive affects one-tap, and emailAndPassword.requireEmailVerification: true does not mitigate the link-time verification change. This issue is fixed in version 1.6.11.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-53516product:"Better-auth Better Auth"http.html:"Better Auth"More intel sources (5)
vuln:CVE-2026-53516vulnerabilities.cve_id: CVE-2026-53516CVE-2026-53516CVE-2026-53516"CVE-2026-53516" exploit -site:nvd.nist.gov