Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-67331

Опубликовано: 01 авг. 2026
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

EPSS

Процентиль: 15%
0.0024
Низкий

8.3 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.3
github
5 дней назад

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

EPSS

Процентиль: 15%
0.0024
Низкий

8.3 High

CVSS3

Дефекты

CWE-639