CVE-2026-67331

Source
https://cve.org/CVERecord?id=CVE-2026-67331
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67331.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-67331
Aliases
Published
2026-08-01T12:22:17.565Z
Modified
2026-08-03T03:30:25.871439456Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass
Details

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67331.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/better-auth/better-auth

Affected ranges

Type
GIT
Repo
https://github.com/better-auth/better-auth
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "1.5.0"
        },
        {
            "fixed": "1.7.0-beta.4"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67331.json"