CVE-2026-67331 PUBLISHED

better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass

Assigner: VulnCheck
Reserved: 29.07.2026 Published: 01.08.2026 Updated: 01.08.2026

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor better-auth
Product scim
Versions Default: unaffected
  • affected from 1.5.0 to 1.7.0-beta.4 (excl.)
  • Version 1.7.0-beta.4 is unaffected

Credits

  • Jvr2022 reporter

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE