Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Better-auth better-auth/oauth-provider
Better-auth passkey |
|
| Vendors & Products |
Better-auth better-auth/oauth-provider
Better-auth passkey |
Sun, 02 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys. | |
| Title | better-auth passkey before 1.4.0 IDOR via delete-passkey | |
| First Time appeared |
Better-auth
Better-auth better-auth\/oauth-provider |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:better-auth:better-auth\/oauth-provider:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Better-auth
Better-auth better-auth\/oauth-provider |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-03T15:37:32.735Z
Reserved: 2026-07-18T12:38:41.077Z
Link: CVE-2025-71400
Updated: 2026-08-03T14:46:46.717Z
Status : Received
Published: 2026-08-02T13:16:52.387
Modified: 2026-08-03T17:16:28.987
Link: CVE-2025-71400
No data.
OpenCVE Enrichment
Updated: 2026-08-03T09:30:17Z