NVD CRITICAL: CVE-2026-67330 — @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1....
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was used for both SCIM provider configuration and account ownership. An
CVE-2026-67330