
🔎 CVE-2026-32130 — SCIM Auth Bypass Found a path normalization issue where encoding U as %55 bypassed authentication. GET /scim/v2/{org}/%55sers/{user_id} HTTP/2 /Users/... → 401 /%55sers/... → 200 OK The endpoint returned the SCIM user object without authentication. https://t.co/ePEyMEYFfi
Post summary
The tweet discloses CVE-2026-32130, describing a path‑normalization authentication bypass via %55 encoding that allows unauthenticated SCIM user access, and includes a link for further details.

