CVE-2026-67331

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.
Configurations

No configuration.

History

01 Aug 2026, 13:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-08-01 13:17

Updated : 2026-08-01 13:17


NVD link : CVE-2026-67331

Mitre link : CVE-2026-67331

CVE.ORG link : CVE-2026-67331


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key