Executive brief
A vulnerability in the Better Auth SCIM plugin allows any logged-in user to take control of another user's personal SCIM provider. This means an attacker could read sensitive configuration data, delete connections, or hijack the authentication token used to manage users. This could lead to unauthorized access to user management systems and potential service disruption.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the @better-auth/scim plugin. By default, the `providerOwnership` option is disabled, causing non-organization ('personal') SCIM providers to be created without a `userId` in the database. The access control logic only denies requests if a `userId` is present and does not match the current user; since the field is null by default, the check passes for any authenticated user. An attacker can use management endpoints like `/scim/generate-token` to rotate a victim's SCIM bearer token, effectively hijacking the SCIM API session and locking out the legitimate owner. The issue is fixed in version 1.7.0-beta.4 by making owner binding mandatory and requiring a schema migration to add a permanent `userId` column.
Affected products
- better-auth @better-auth/scim >= 1.5.0, < 1.7.0-beta.4
Timeline
- 2026-05-31: disclosed: Initial disclosure to vendor
- 2026-07-07: advisory: GitHub Advisory published
- 2026-07-07: patched: Fix released in version 1.7.0-beta.4