better-auth Vulnerabilities and Affected Products
Vulnerabilities associated with scim.
Products
Clear product- better-auth25 vulnerabilities
- oauth-provider2 vulnerabilities
- scim2 vulnerabilities
- better-icons1 vulnerability
- passkey1 vulnerability
- sso1 vulnerability
- stripe1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-67331HIGH | better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypassbetter-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token. CWE-639Aug 1, 2026 | CVSS8.7v4.0 | EPSS0.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-67330CRITICAL | better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was used for both SCIM provider configuration and account ownership. An authenticated user could mint a SCIM token whose provider ID collided with an existing provider nam… CWE-20Aug 1, 2026 | CVSS9.4v4.0 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |