Known Vulnerabilities for Scim by Better-auth
Listed below are 9 of the newest known vulnerabilities associated with "Scim" by "Better-auth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72537 json | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72534 json | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-67334 json | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67331 json | better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by def... | Not Provided | 2026-08-01 | 2026-08-14 |
| CVE-2026-67330 json | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-bet... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-48170 json | `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH... | Not Provided | 2026-08-07 | 2026-08-10 |
| CVE-2026-43640 json | Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organiz... | Not Provided | 2026-05-11 | 2026-07-14 |
| CVE-2026-15212 json | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. T... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2025-10903 json | GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 bef... | Not Provided | 2026-08-26 | 2026-08-26 |