CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-67332: oauth-provider 1.4.8 to before 1.7.0-beta.4

CVE-2026-67332. CVSS 3.1 base score 6.4 (MEDIUM, Vendor/CNA). EPSS 0.0026 (percentile 0.16145), scored 2026-10-06.

Affected technology

oauth-provider · 1.4.8 to before 1.7.0-beta.4
better-auth

Description’s affected range: before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing intended authorization boundaries. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-285
CCR priority
25.7 /100 (P4)
CVSS 3.1
6.4 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N · Vendor/CNA
EPSS
0.0026 · percentile 0.16217 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-67332.html