How to use this reference
Editorial reasoning: an unknown owner is a separate authorization state, not an implicit shared resource. Review creation, migration and subsequent management together. The fix mandates owner binding and makes legacy ownerless records fail closed; administrators must resolve those records rather than assuming a package upgrade assigns legitimate ownership.
Before reading
- SCIM provisioning, bearer-token authority and object ownership concepts
Context and limits
- Exposure concerns ownerless personal SCIM providers in applications with multiple signed-in users. Ownership enforcement is disabled by default, but enabling it later does not protect pre-existing ownerless providers; those require separate remediation. Organization-bound providers use membership and role checks. Affected versions are 1.5.0 through 1.7.0-beta.3.
- The advisory identifies fixes in 1.7.0-beta.4 and 1.7.0; the 1.6.x line requires mitigation. The June 2, 2026 vendor bulletin independently identifies the SCIM-specific beta fix, rather than treating its general stable-release guidance as sufficient.
- gustavovalverde published the notice; Jvr2022 is credited as reporter. Impact is maintainer-reported; compromise of a deployed instance is not established. Patch-release dates remain unverified and are not resource-edition dates.
Sources and provenance
- SCIM personal-provider ownership advisory Better Auth · reviewed 2026-10-03
- Security update: June 2026 Better Auth · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.