CVE-2026-67331 Details
Description
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.
A vulnerability exists in better-auth SCIM versions 1.5.0 prior to 1.7.0-beta.4, where non-organization SCIM providers are not automatically linked to their creators. This oversight enables authenticated users to manipulate other users' SCIM providers. Exploitation allows attackers to regenerate SCIM bearer tokens, invalidate valid tokens, and authenticate to SCIM API routes using the attacker-controlled token.
Users can upgrade to better-auth SCIM version 1.7.0-beta.4 or later. This version enforces owner binding for non-organization providers, making it a breaking change. After upgrading, run the schema migration to update the database. For those unable to upgrade, SCIM provider ownership can be enabled in the plugin registration, or access to SCIM management endpoints can be restricted at the network edge.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 1, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/better-auth/better-auth/security/advisories/GHSA-j8v8-g9cx-5qf4 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/better-auth/better-auth/security/advisories/GHSA-j8v8-g9cx-5qf4 | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/better-auth-scim-before-beta-4-authorization-bypass | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| better-auth SCIM | >= 1.5.0, < 1.7.0-beta.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2026 | New CVE Received | [email protected] |
Volerion