Junglewise Threat Intelligence

CVE-2026-67330: better-auth SCIM authorization bypass via provider ID collision

CVE-2026-67330 · Severity: critical · CVSS 9.9 · Published 2026-08-01

Technologies: Better-Auth Scim. Vendors: Better-Auth.

Executive brief

@better-auth/scim is a plugin that manages user provisioning and account linking for the better-auth authentication framework. A vulnerability in SCIM token generation allowed authenticated users to create tokens using provider IDs that matched existing account providers (SSO, SAML, OIDC, social providers), enabling them to gain unauthorized access to, modify, or delete user accounts and sessions they did not own. An attacker with basic authenticated access could take over arbitrary user accounts, reset emails, or disable users enterprise-wide.

Technical details

The vulnerability is an authorization bypass in SCIM token issuance and routing (CWE-20: Improper Input Validation). The root cause: SCIM token issuance did not validate that the provider ID in a new SCIM token was unique or different from existing account provider namespaces (SSO, SAML, OIDC, OAuth, social). SCIM user routes then queried accounts by providerId without verifying that the token actually owned those accounts, treating colliding provider IDs as authorization keys. An authenticated attacker could mint a SCIM token with a provider ID matching an existing provider, then use SCIM routes to list, read, update (including email changes without uniqueness checks), and delete accounts under that namespace. The attack requires: (1) @better-auth/scim plugin enabled, (2) authenticated user able to generate SCIM tokens (default policy affected), (3) existing SSO/SAML/OIDC/OAuth/social provider accounts to collide with. Impact includes account takeover, session hijacking, unauthorized email changes, and user deprovisioning. Fixed in versions 1.6.22, 1.7.0-beta.10, and 1.7.0-rc.0.

Affected products

  • better-auth SCIM >=1.4.0-beta.27 through <=1.6.21 and >=1.7.0-beta.0 through <=1.7.0-beta.9

Timeline

  • 2026-06-26: disclosed: GitHub Security Advisory GHSA-rjg6-39jm-rgg4 published
  • 2026-08-01: advisory: NVD CVE-2026-67330 published
  • 2026-08-01: patched: Patches released: 1.6.22, 1.7.0-beta.10 (1.7.0-rc.0)

References

Related threats