Executive brief
A vulnerability in the Better Auth SCIM plugin allows authenticated users to gain unauthorized control over other user accounts. By creating a specially crafted token, an attacker can modify profile information, change email addresses, or even delete user accounts belonging to other login providers like Google or GitHub. Additionally, a separate bug prevents the system from properly deactivating users when requested by an identity provider, potentially leaving access active for terminated employees.
Technical details
The @better-auth/scim plugin fails to validate that a SCIM provider ID does not collide with existing account provider namespaces (e.g., SSO, OIDC, SAML). An authenticated user can mint a SCIM token with a colliding ID, allowing the SCIM middleware to resolve and manage account rows it does not own. This enables unauthorized listing, modification, and deletion of users via SCIM endpoints. Furthermore, the plugin failed to model the 'active' attribute, causing deactivation requests to be ignored, and lacked email uniqueness checks during PUT/PATCH operations, which could lead to account hijacking or data corruption. Fixes are available in versions 1.6.22 and 1.7.0-beta.10.
Affected products
- Better Auth @better-auth/scim >= 1.4.0-beta.27, <= 1.6.21; >= 1.7.0-beta.0, <= 1.7.0-beta.9
Timeline
- 2026-06-26: disclosed
- 2026-07-24: advisory
References
- https://github.com/better-auth/better-auth/security/advisories/GHSA-rjg6-39jm-rgg4
- https://github.com/better-auth/better-auth/pull/10242
- https://github.com/better-auth/better-auth/commit/7c126dcd1aad24468ec37e876545c1d083d8acca
- https://github.com/better-auth/better-auth/releases/tag/v1.6.22
- https://github.com/better-auth/better-auth/releases/tag/v1.7.0-beta.10
- https://api.github.com/repos/better-auth/better-auth/security-advisories/GHSA-rjg6-39jm-rgg4