CVE-2026-67331

Source
https://cve.org/CVERecord?id=CVE-2026-67331
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67331.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-67331
Aliases
Published
2026-08-01T12:22:17Z
Modified
2026-09-10T03:30:31Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass
Details

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67331.json"
}
References

Affected packages

Git / github.com/better-auth/better-auth

Affected ranges

Type
GIT
Repo
https://github.com/better-auth/better-auth
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.5.0"
        },
        {
            "fixed": "1.7.0-beta.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67331.json"