CVE-2026-37171 Details
Description
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.
A vulnerability in SuperTokens Inc. SuperTokens Core versions 6.0.0 through 11.4.0 allows an authenticated user in one tenant to access sessions, data, and endpoints of another tenant. This issue arises because the application does not properly validate tenant claims in session tokens against the tenant context of incoming requests, leading to a breakdown in multitenant isolation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://whitenbaker.com/supertokens-core-multitenant-advisory/ | CISA-ADP | |
| http://www.openwall.com/lists/oss-security/2026/09/09/4 | CVE | |
| https://whitenbaker.com/supertokens-core-multitenant-advisory | [email protected] | AdvisoryExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| SuperTokens Inc. SuperTokens Core | >= 6.0.0, <= 11.4.0 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | [email protected] |
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | CVE Modified | CVE |
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion