AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-37171

MEDIUM · CVSS 5.9 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

SuperTokens Core versions 6.0.0 to 11.4.0 exhibit a vulnerability due to inadequate tenant separation, enabling authenticated users from one tenant to access the sessions, data, and endpoints of another tenant. This flaw poses a risk of unauthorized data exposure and potential data manipulation across tenants. Organizations utilizing SuperTokens for multi-tenant applications should prioritize addressing this vulnerability to safeguard sensitive information and maintain tenant isolation.

CVE
CVE-2026-37171
Severity
MEDIUM
CVSS
5.9
EPSS
0.16%

Original NVD Description

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.