---
id: CVE-2026-67331
title: >-
  better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind
  non-organization SCIM providers to their creator by default, allowing
  authenticated users to manage other users' providers
summary: >-
  better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind
  non-organization SCIM providers to their creator by default, allowing
  authenticated users to manage other users' providers. Attackers can regenerate
  SCIM bearer tokens…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-639
published: '2026-08-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:34:34.997'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67331'
references:
  - url: >-
      https://github.com/better-auth/better-auth/security/advisories/GHSA-j8v8-g9cx-5qf4
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/better-auth-scim-before-beta-4-authorization-bypass
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/better-auth/better-auth/security/advisories/GHSA-j8v8-g9cx-5qf4
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00298
epssPercentile: 0.22629
ingestedAt: '2026-08-02T07:18:02.475Z'
---

## Overview

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
