PatchSiren cyber security CVE debrief
CVE-2026-67331 better-auth CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:03.833Z and has not been modified since then. The vulnerability affects better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4, allowing authenticated users to manage other users' providers due to a binding issue. This issue enables attackers to regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token. Limited source detail suggests verifying installations, monitoring for suspicious activity, and updating to version 1.7.0-beta.4 or later. Defensive verification tasks are needed due to limited evidence.
- Vendor
- better-auth
- Product
- scim
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
Users of better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 should be aware of this binding issue and take necessary actions to secure their installations. This includes verifying installed versions, restricting access to SCIM API routes, and monitoring for suspicious token regeneration activity. Security teams and operators managing SCIM providers should prioritize updates and compensating controls for authentication and authorization.
Technical summary
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default. This allows authenticated users to manage other users' providers, regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token. The issue requires updating to version 1.7.0-beta.4 or later. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. Official advisories or CVE records should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review. Exceptions should be tracked, remediated assets should be retested, and the item should only be closed after evidence is documented.
Defensive priority
Authenticated users can manage other users' SCIM providers due to a binding issue in better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4, allowing token regeneration and invalidation.
Recommended defensive actions
- Inventory and verify installed better-auth SCIM versions.
- Restrict access to SCIM API routes.
- Monitor for suspicious token regeneration activity.
- Update to version 1.7.0-beta.4 or later.
- Implement compensating controls for authentication and authorization.
Evidence notes
The CVE-2026-67331 record indicates that better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 have a binding issue, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens and authenticate to SCIM API routes. Limited source detail suggests verifying installations, monitoring for suspicious activity, and updating to version 1.7.0-beta.4 or later. Defensive verification tasks are needed due to limited evidence.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:03.833Z and has not been modified since then.