CVE-2026-37171 PUBLISHED

Assigner: mitre
Reserved: 06.04.2026 Published: 07.08.2026 Updated: 07.08.2026

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

Metrics

CVSS Vector: CVSS:3.1/AC:H/AV:N/A:N/C:H/I:L/PR:L/S:U/UI:N
CVSS Score: 5.9

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text