๐Ÿ” CVE Alert

CVE-2026-67330

CRITICAL 9.9

better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was used for both SCIM provider configuration and account ownership. An authenticated user could mint a SCIM token whose provider ID collided with an existing provider namespace, causing SCIM user routes to resolve account rows the token never provisioned. This allowed listing, reading, updating (including rewriting global profile/email fields without uniqueness checks), and deleting global user accounts and sessions, resulting in account takeover and unauthorized deprovisioning. Fixed in 1.6.22 and 1.7.0-beta.10 (1.7.0-rc.0).

CWE CWE-20
Vendor better-auth
Product scim
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for better-auth scim

Be the first to know when new critical vulnerabilities affecting better-auth scim are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

better-auth / scim
1.4.0-beta.27 < *
better-auth / scim
1.7.0-beta.0 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/better-auth/better-auth/security/advisories/GHSA-rjg6-39jm-rgg4 vulncheck.com: https://www.vulncheck.com/advisories/better-auth-scim-beta-27-through-account-takeover-via-provider-id-collision