ZeroHour
oss-securitypublished ()ingested

CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)

mediumVulnerabilityimportance 45CVE-2026-37171
AI summary · glm-5.3-flash

CVE-2026-37171: SuperTokens Core 6.0.0-11.4.0 lacks tenant separation in session operations, enabling cross-tenant access.

CVE-2026-37171 (CWE-863, Incorrect Authorization) affects SuperTokens Core, the self-hosted authentication server by SuperTokens Inc., versions 6.0.0 through 11.4.0. The Core lacks tenant separation in session operations, permitting cross-tenant authorization bypass. The CVE is published, with advisory entries NVD and GitHub GHSA-j7vw-hh5c-2w6x; the disclosure does not mention any observed exploitation.

  • Cross-tenant authorization flaw (CWE-863) in session operations
  • Affects SuperTokens Core versions 6.0.0 through 11.4.0
  • Tracked as GHSA-j7vw-hh5c-2w6x on GitHub

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-37171
A lack of tenant separation in SuperTokens Inc.

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

NVD description · AI analysis pending
5.9<1%
Full article

Posted by Mr. Gatto on Sep 09 Hello, This is a disclosure for CVE-2026-37171, a cross-tenant authorization flaw in SuperTokens Core, the self-hosted authentication server by SuperTokens Inc. Affected: SuperTokens Core (supertokens-core) versions 6.0.0 through 11.4.0. CWE: CWE-863 (Incorrect Authorization). CVE: CVE-2026-37171 (published; NVD and GitHub Advisory GHSA-j7vw-hh5c-2w6x). Summary ------- SuperTokens Core lacks tenant separation in session operations. The Core...

This source does not provide full text. Read it at seclists.org.