GitHub Security Advisory (GHSA-j8v8-g9cx-5qf4)Vendor advisory
https://github.com/better-auth/better-auth/security/advisories/GHSA-j8v8-g9cx-5qf4 CVE-2026-67331
HIGH
better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass
Record summary
CVE-2026-67331 has a selected CVSS score of 8.7 (high).
Description
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 1.5.0 to < 1.7.0-beta.4 | affected |
| 1.7.0-beta.4 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-67331 VulnCheck Advisory: better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization BypassThird-party advisory
https://www.vulncheck.com/advisories/better-auth-scim-before-beta-4-authorization-bypass