Authorization Bypass in Better-Auth Plugin for SCIM by Better-Auth
CVE-2026-67330
What is CVE-2026-67330?
The Better-Auth SCIM plugin, specifically in versions from 1.4.0-beta.27 to 1.6.21 and 1.7.0-beta.0 to 1.7.0-beta.9, contains a significant authorization bypass vulnerability. This issue arises from improper handling of SCIM token issuance, where the plugin does not adequately reject provider IDs that are already in use by various identity providers, including SSO, SAML, OIDC, and OAuth services. As a result, authenticated users can generate SCIM tokens that conflict with existing provider identifiers. This allows them to access, modify, and delete user accounts without proper permissions—leading to potential account takeovers. Users are advised to upgrade to version 1.6.22 or 1.7.0-beta.10 (or later) to mitigate these vulnerabilities.
Affected Version(s)
scim 1.4.0-beta.27
scim 1.7.0-beta.0
