Vulnerabilidad · Publicado 01/08/2026
Las versiones 1.5.0 a 1.7.0-beta.3 de better-auth SCIM presentan una falla de autorización que permite a usuarios autenticados gestionar proveedores SCIM creados por otros usuarios. Un atacante puede regenerar tokens bearer, invalidar tokens legítimos y autenticarse en rutas de API SCIM con tokens bajo su control. Este fallo afecta sistemas de identidad y acceso en empresas con infraestructura de autenticación centralizada.
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.
Score: 8.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CWE-639
Publicado en NIST NVD.