CVE-2026-67331
Received Received - Intake

better-auth SCIM Provider Token Management Flaw

Vulnerability report for CVE-2026-67331, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: VulnCheck

Description

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
better-auth better-auth From 1.5.0 (inc) to 1.7.0-beta.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in better-auth SCIM versions 1.5.0 to 1.7.0-beta.4 allows authenticated users to manage non-organization SCIM providers created by others. Attackers can regenerate tokens, invalidate legitimate ones, and authenticate to SCIM API routes using attacker-controlled tokens.

Detection Guidance

Check for unauthorized SCIM bearer token regeneration or invalidation events in application logs. Monitor for unexpected authentication to SCIM API routes from non-organization providers. Review user access logs for unusual management activities across providers.

Impact Analysis

This vulnerability allows attackers to take control of other users' SCIM providers, potentially leading to unauthorized access, data manipulation, or service disruption. It compromises the integrity and confidentiality of user accounts and associated data.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection principles and HIPAA's security requirements. It may result in non-compliance, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade better-auth to version 1.7.0-beta.4 or later. Review and revoke any potentially compromised SCIM bearer tokens. Implement strict access controls to prevent unauthorized token management. Monitor for suspicious activities post-upgrade.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67331. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart