Authorization Bypass in Better-Auth Plugin for SCIM by Better-Auth
CVE-2026-67330

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67330?

The Better-Auth SCIM plugin, specifically in versions from 1.4.0-beta.27 to 1.6.21 and 1.7.0-beta.0 to 1.7.0-beta.9, contains a significant authorization bypass vulnerability. This issue arises from improper handling of SCIM token issuance, where the plugin does not adequately reject provider IDs that are already in use by various identity providers, including SSO, SAML, OIDC, and OAuth services. As a result, authenticated users can generate SCIM tokens that conflict with existing provider identifiers. This allows them to access, modify, and delete user accounts without proper permissions—leading to potential account takeovers. Users are advised to upgrade to version 1.6.22 or 1.7.0-beta.10 (or later) to mitigate these vulnerabilities.

Affected Version(s)

scim 1.4.0-beta.27

scim 1.7.0-beta.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.