PT-2026-67310 · Npm · @Better-Auth/Scim
CVE-2026-67330
·
Published
2026-08-01
·
Updated
2026-08-01
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
@better-auth/scim versions 1.4.0-beta.27 through 1.6.21
@better-auth/scim versions 1.7.0-beta.0 through 1.7.0-beta.9
Description
An authorization bypass exists where SCIM token issuance fails to reject provider IDs already utilized by existing SSO, SAML, OIDC, generic OAuth, or social account providers. Because the same logical provider ID is used for both SCIM provider configuration and account ownership, an authenticated user can create a SCIM token with a provider ID that collides with an existing provider namespace. This causes SCIM user routes to resolve account rows that the token did not provision, enabling the listing, reading, updating, and deleting of global user accounts and sessions. This includes the ability to rewrite global profile and email fields without uniqueness checks, leading to account takeover and unauthorized deprovisioning.
Recommendations
Update versions 1.4.0-beta.27 through 1.6.21 to version 1.6.22.
Update versions 1.7.0-beta.0 through 1.7.0-beta.9 to version 1.7.0-beta.10 (1.7.0-rc.0).
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Better-Auth/Scim