{"apiVersion":"1.0","identifier":"CVE-2026-80192","description":"@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization owner/administrator to register an SSO provider for an arbitrary domain and have users with matching email domains added to the attacker-s organization with default member permissions. When domain verification is enabled, a race condition between the verify-domain and update-provider endpoints can apply completed DNS proof to a different domain; combined with implicit account linking, this can link an attacker-controlled identity provider to an existing user account. Exploitation requires the SSO plugin (and, for the org-assignment path, the organization plugin) with the relevant configuration enabled.","publishedAt":"2026-08-26T05:18:26","lastModifiedAt":"2026-08-26T14:17:16","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80192","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","epssProbability":0.00274,"riskScore":0.83,"affectedProduct":"@better-auth/sso","affectedVersions":"<1.6.27, <1.4.8, <1.7.0-rc.5","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-80192","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-80192","en":"https://www.redsauce.net/en/cves/CVE-2026-80192","fr":"https://www.redsauce.net/fr/cves/CVE-2026-80192","pt":"https://www.redsauce.net/pt/cves/CVE-2026-80192","de":"https://www.redsauce.net/de/cves/CVE-2026-80192","sk":"https://www.redsauce.net/sk/cves/CVE-2026-80192","el":"https://www.redsauce.net/el/cves/CVE-2026-80192"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-80192"}}