CVE-2026-67330
Received Received - Intake

Authorization Bypass in Better Auth SCIM Plugin

Vulnerability report for CVE-2026-67330, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: VulnCheck

Description

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was used for both SCIM provider configuration and account ownership. An authenticated user could mint a SCIM token whose provider ID collided with an existing provider namespace, causing SCIM user routes to resolve account rows the token never provisioned. This allowed listing, reading, updating (including rewriting global profile/email fields without uniqueness checks), and deleting global user accounts and sessions, resulting in account takeover and unauthorized deprovisioning. Fixed in 1.6.22 and 1.7.0-beta.10 (1.7.0-rc.0).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
better-auth scim From 1.4.0-beta.27 (inc) to 1.6.21 (inc)
better-auth scim From 1.7.0-beta.0 (inc) to 1.7.0-beta.9 (inc)
better-auth scim 1.6.22
better-auth scim 1.7.0-beta.10
better-auth scim 1.7.0-rc.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in the @better-auth/scim plugin versions between 1.4.0-beta.27 and 1.6.21, and 1.7.0-beta.0 and 1.7.0-beta.9. It allows an authenticated user to exploit a collision in provider IDs to gain unauthorized access to SCIM user routes. This can lead to listing, reading, updating, or deleting global user accounts and sessions, resulting in account takeover and unauthorized deprovisioning.

Impact Analysis

If you use the affected versions of @better-auth/scim, an attacker could exploit this flaw to take over accounts, modify or delete user data, and deprovision users without authorization. This could lead to data breaches, loss of sensitive information, and disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access or deletion of user data, violating GDPR's data protection principles and HIPAA's security and privacy requirements. It may result in non-compliance, legal penalties, and loss of trust in handling sensitive data.

Mitigation Strategies

Immediately upgrade to a patched version of @better-auth/scim: either 1.6.22 or 1.7.0-beta.10 (or later). Review all SCIM token issuance logs for unusual provider ID collisions or unauthorized account modifications. Audit global user accounts and sessions for signs of tampering or unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67330. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart