CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)
CVE-2026-37171: SuperTokens Core 6.0.0-11.4.0 lacks tenant separation in session operations, enabling cross-tenant access.
CVE-2026-37171 (CWE-863, Incorrect Authorization) affects SuperTokens Core, the self-hosted authentication server by SuperTokens Inc., versions 6.0.0 through 11.4.0. The Core lacks tenant separation in session operations, permitting cross-tenant authorization bypass. The CVE is published, with advisory entries NVD and GitHub GHSA-j7vw-hh5c-2w6x; the disclosure does not mention any observed exploitation.
- Cross-tenant authorization flaw (CWE-863) in session operations
- Affects SuperTokens Core versions 6.0.0 through 11.4.0
- Tracked as GHSA-j7vw-hh5c-2w6x on GitHub
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-37171 | A lack of tenant separation in SuperTokens Inc. A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant. NVD description · AI analysis pending | 5.9 | <1% | — | — |
Posted by Mr. Gatto on Sep 09 Hello, This is a disclosure for CVE-2026-37171, a cross-tenant authorization flaw in SuperTokens Core, the self-hosted authentication server by SuperTokens Inc. Affected: SuperTokens Core (supertokens-core) versions 6.0.0 through 11.4.0. CWE: CWE-863 (Incorrect Authorization). CVE: CVE-2026-37171 (published; NVD and GitHub Advisory GHSA-j7vw-hh5c-2w6x). Summary ------- SuperTokens Core lacks tenant separation in session operations. The Core...
This source does not provide full text. Read it at seclists.org.