{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/scim/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-67331"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["scim"],"_cs_severities":["high"],"_cs_tags":["cve-2026-67331","authorization-bypass","scim","better-auth"],"_cs_type":"advisory","_cs_vendors":["better-auth"],"content_html":"\u003cp\u003eThe better-auth SCIM package (versions 1.5.0 through 1.6.x) contains a critical authorization flaw tracked as CVE-2026-67331. The vulnerability stems from the application's failure to properly bind non-organization SCIM providers to the specific user account that created them. By default, the system assumes global accessibility for these provider objects, which results in an insecure direct object reference (IDOR) or similar authorization bypass condition.\u003c/p\u003e\n\u003cp\u003eThis issue allows any authenticated user within the application to perform administrative actions on SCIM providers owned by other users. The impact is significant, as an attacker can list, modify, or delete existing providers, invalidate legitimate SCIM bearer tokens, and generate new tokens under the context of the victim's provider configuration. This effectively permits an attacker to perform account takeover or unauthorized data synchronization by intercepting or manipulating SCIM API traffic. Organizations using affected versions are advised to upgrade to 1.7.0-beta.4 or later immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to fully control the SCIM integration lifecycle of other users within the platform. This leads to the compromise of identity synchronization processes, potential unauthorized provisioning or deprovisioning of accounts, and the ability to exfiltrate or modify sensitive identity data transmitted through SCIM. The vulnerability has a CVSS v3.1 base score of 8.3, reflecting the high risk to confidentiality and integrity in enterprise environments relying on SCIM for user lifecycle management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the better-auth SCIM package to version 1.7.0-beta.4 or higher to resolve the authorization logic flaw documented in CVE-2026-67331.\u003c/li\u003e\n\u003cli\u003eAudit existing SCIM provider configurations in your environment to identify any unauthorized provider objects or unexpected token changes.\u003c/li\u003e\n\u003cli\u003eReview web access logs for anomalous API activity directed at SCIM endpoints, specifically looking for repeated modifications of token resources by non-administrative users.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T13:54:41Z","date_published":"2026-08-01T13:54:41Z","id":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-scim-auth-bypass/","summary":"An authorization bypass vulnerability in better-auth SCIM (CVE-2026-67331) allows authenticated users to manage and manipulate SCIM providers belonging to other users due to missing owner-binding checks.","title":"Authorization Bypass Vulnerability in better-auth SCIM","url":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-scim-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Scim","version":"https://jsonfeed.org/version/1.1"}