SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-71400

HIGH · CVSS 7.1 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

Authenticated users of better-auth passkey versions prior to 1.4.0 are vulnerable to an insecure direct object reference (IDOR) flaw in the passkey deletion endpoint, enabling them to delete arbitrary passkeys by ID. This vulnerability allows attackers with valid sessions to exploit the endpoint by submitting crafted requests, potentially removing passkeys belonging to other users. Organizations utilizing affected versions should prioritize patching this vulnerability to safeguard user data and maintain system integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71400
Severity
HIGH
CVSS
7.1
EPSS
0.20%

Original NVD Description

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys.