<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-67331 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-67331/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 01 Aug 2026 13:54:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-67331/feed.xml" rel="self" type="application/rss+xml"/><item><title>Authorization Bypass Vulnerability in better-auth SCIM</title><link>https://feed.craftedsignal.io/briefs/2026-08-better-auth-scim-auth-bypass/</link><pubDate>Sat, 01 Aug 2026 13:54:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-better-auth-scim-auth-bypass/</guid><description>An authorization bypass vulnerability in better-auth SCIM (CVE-2026-67331) allows authenticated users to manage and manipulate SCIM providers belonging to other users due to missing owner-binding checks.</description><content:encoded><![CDATA[<p>The better-auth SCIM package (versions 1.5.0 through 1.6.x) contains a critical authorization flaw tracked as CVE-2026-67331. The vulnerability stems from the application's failure to properly bind non-organization SCIM providers to the specific user account that created them. By default, the system assumes global accessibility for these provider objects, which results in an insecure direct object reference (IDOR) or similar authorization bypass condition.</p>
<p>This issue allows any authenticated user within the application to perform administrative actions on SCIM providers owned by other users. The impact is significant, as an attacker can list, modify, or delete existing providers, invalidate legitimate SCIM bearer tokens, and generate new tokens under the context of the victim's provider configuration. This effectively permits an attacker to perform account takeover or unauthorized data synchronization by intercepting or manipulating SCIM API traffic. Organizations using affected versions are advised to upgrade to 1.7.0-beta.4 or later immediately.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthorized users to fully control the SCIM integration lifecycle of other users within the platform. This leads to the compromise of identity synchronization processes, potential unauthorized provisioning or deprovisioning of accounts, and the ability to exfiltrate or modify sensitive identity data transmitted through SCIM. The vulnerability has a CVSS v3.1 base score of 8.3, reflecting the high risk to confidentiality and integrity in enterprise environments relying on SCIM for user lifecycle management.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the better-auth SCIM package to version 1.7.0-beta.4 or higher to resolve the authorization logic flaw documented in CVE-2026-67331.</li>
<li>Audit existing SCIM provider configurations in your environment to identify any unauthorized provider objects or unexpected token changes.</li>
<li>Review web access logs for anomalous API activity directed at SCIM endpoints, specifically looking for repeated modifications of token resources by non-administrative users.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-67331</category><category>authorization-bypass</category><category>scim</category><category>better-auth</category></item></channel></rss>