Tag
high
advisory
Authorization Bypass Vulnerability in better-auth SCIM
1 TTP 1 CVEAn authorization bypass vulnerability in better-auth SCIM (CVE-2026-67331) allows authenticated users to manage and manipulate SCIM providers belonging to other users due to missing owner-binding checks.
scim
cve-2026-67331
authorization-bypass
better-auth
1t
1c
critical
advisory
scimPatch vulnerable to prototype pollution via unfiltered keys in patch
3 TTPsThe `scim-patch` Node.js library, versions up to and including 0.9.0, is critically vulnerable to prototype pollution (CVE-2026-48170) when processing SCIM PATCH operations, allowing an attacker to modify `Object.prototype` process-wide through crafted `__proto__` keys in the request body, leading to potential privilege escalation or denial of service.
scim-patch <= 0.9.0
prototype-pollution
cve
node.js
scim
critical-vulnerability
3t
high
advisory
Kanidm SCIM Filter Stack Exhaustion Vulnerability
2 rules 3 TTPsAn unauthenticated GET request with deeply nested parentheses in the SCIM filter parameter can cause stack exhaustion and process termination in Kanidm, leading to denial of service.
kanidm_proto +1
denial-of-service
scim
stack-overflow
2r
3t