Known Vulnerabilities for Scim by Better-auth
Listed below are 7 of the newest known vulnerabilities associated with "Scim" by "Better-auth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67334 json | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67331 json | better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by def... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67330 json | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-bet... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-46689 json | Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint ... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-46425 json | Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only tw... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-43640 json | Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organiz... | Not Provided | 2026-05-11 | 2026-07-14 |
| CVE-2026-15212 json | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. T... | Not Provided | 2026-07-23 | 2026-07-24 |