PT-2026-67310 · Npm · @Better-Auth/Scim

CVE-2026-67330

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @better-auth/scim versions 1.4.0-beta.27 through 1.6.21 @better-auth/scim versions 1.7.0-beta.0 through 1.7.0-beta.9
Description An authorization bypass exists where SCIM token issuance fails to reject provider IDs already utilized by existing SSO, SAML, OIDC, generic OAuth, or social account providers. Because the same logical provider ID is used for both SCIM provider configuration and account ownership, an authenticated user can create a SCIM token with a provider ID that collides with an existing provider namespace. This causes SCIM user routes to resolve account rows that the token did not provision, enabling the listing, reading, updating, and deleting of global user accounts and sessions. This includes the ability to rewrite global profile and email fields without uniqueness checks, leading to account takeover and unauthorized deprovisioning.
Recommendations Update versions 1.4.0-beta.27 through 1.6.21 to version 1.6.22. Update versions 1.7.0-beta.0 through 1.7.0-beta.9 to version 1.7.0-beta.10 (1.7.0-rc.0).

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67330

Affected Products

@Better-Auth/Scim