« Volver al listado

CVE-2026-53517

Estado: AnalizadaAlta (8.1)—

Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests with the same parent refresh token to pass the revoked check and create forked refresh-token families; the vulnerable range also includes embedded better-auth plugin versions before 1.6.0. This issue is fixed in version 1.6.11.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:L permite acceso remoto autenticado a servicio (T1210). La condición de carrera en token refresh permite escalada de privilegios y sesiones no autorizadas (T1068, T1078).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-53517",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-53517",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-15T19:20:42.640935Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "better-auth",
          "product": "better-auth",
          "versions": [
            {
              "status": "affected",
              "version": ">= 1.4.8-beta.7, < 1.6.0"
            }
          ]
        },
        {
          "vendor": "@better-auth",
          "product": "oauth-provider",
          "versions": [
            {
              "status": "affected",
              "version": ">= 1.6.0, < 1.6.11"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-15T18:16:48.107",
  "references": [
    {
      "url": "https://github.com/better-auth/better-auth/commit/c6918ecc9e3a75892169415d7f6c95b591b6a52d",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-392p-2q2v-4372",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        },
        {
          "lang": "en",
          "value": "CWE-367"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests with the same parent refresh token to pass the revoked check and create forked refresh-token families; the vulnerable range also includes embedded better-auth plugin versions before 1.6.0. This issue is fixed in version 1.6.11."
    }
  ],
  "lastModified": "2026-07-21T16:00:22.173",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:better-auth:better-auth\\/oauth-provider:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CF0531C-8739-41D0-96F5-9A19A04F2E19",
              "versionEndExcluding": "1.6.11",
              "versionStartIncluding": "1.6.0"
            },
            {
              "criteria": "cpe:2.3:a:better-auth:better_auth:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5552846-37CD-440F-A3F5-51DC4192ECF3",
              "versionEndExcluding": "1.6.11",
              "versionStartIncluding": "1.4.9"
            },
            {
              "criteria": "cpe:2.3:a:better-auth:better_auth:1.4.8:-:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DEBDFBD-94A3-4E7A-837C-6761070F416D"
            },
            {
              "criteria": "cpe:2.3:a:better-auth:better_auth:1.4.8:beta7:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44F50292-6720-45F7-8100-DC80201A6DD5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}