Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-41427 | better-auth oauth-provider up to 1.6.4/1.7.0-beta.1 OAuth Client Creation Endpoint authorization (EUVD-2026-25617)
A vulnerability, which was classified as problematic, was found in better-auth oauth-provider up to 1.6.4/1.7.0-beta.1. This issue affects some unknown…
A vulnerability, which was classified as problematic, was found in better-auth oauth-provider up to 1.6.4/1.7.0-beta.1. This issue affects some unknown processing of the component OAuth Client Creation Endpoint. The manipulation results in incorrect authorization.
This vulnerability is known as CVE-2026-41427. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
This vulnerability is known as CVE-2026-41427. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CISA-SSVC-Triage (vulnrichment)CVE-2026-41427
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-04-27T13:42:15.023332Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com