Authorization Bypass in better-auth SCIM Affects User Management
CVE-2026-67331
8.7HIGH
What is CVE-2026-67331?
The better-auth SCIM service, specifically versions ranging from 1.5.0 up to 1.6.0 and including version 1.7.0-beta.4, contains a significant vulnerability that permits authenticated users to manage non-organization SCIM providers. This occurs due to a failure in binding these providers to their respective creators by default. Consequently, attackers can exploit this flaw to regenerate SCIM bearer tokens, invalidate legitimate tokens, and gain unauthorized access to SCIM API routes using token control. This vulnerability requires immediate attention to secure user management processes and protect sensitive operations.
Affected Version(s)
scim 1.5.0 < 1.7.0-beta.4
scim 1.7.0-beta.4
