THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67330 (CRITICAL 9.9) — @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social acc

[NVD] CVE-2026-67330 (CRITICAL 9.9) — @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social acc

mednvdPublished 2026-08-01

CVE-2026-67330 CVSS: 9.9 CRITICAL Published: 2026-08-01T13:17:03.677

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID w

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67330