Showing 2 vulnerabilities on this page for scim

Signals CISA KEV Ransomware Nuclei
better-auth vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

CWE-639Aug 1, 2026
CVSS8.7v4.0EPSS0.24%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was used for both SCIM provider configuration and account ownership. An authenticated user could mint a SCIM token whose provider ID collided with an existing provider nam

CWE-20Aug 1, 2026
CVSS9.4v4.0EPSS0.352%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX