Sceawere

Vulnerability Detail

CVE-2026-37171UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SuperTokens Core Tenant Separation Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
23h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-08-07T14:16:59.237Z",
  "pubdate": "2026-08-07T14:16:59.237Z",
  "executiveSummary": "A critical lack of tenant separation vulnerability has been identified in SuperTokens Inc. SuperTokens Core affecting versions v6.0.0 to v11.4.0. This authorization bypass vulnerability enables an authenticated party operating within one tenant to illicitly access sessions, sensitive data, and restricted endpoints belonging to entirely separate tenants within the same deployment instance.\nThe vulnerability poses severe risk implications for multi-tenant architectures relying on SuperTokens Core for identity and session management. By exploiting this flaw, an unauthorized attacker with standard user authentication in a single tenant can pivot horizontally to compromise the data integrity and confidentiality of isolated tenant environments.\nSuccessful exploitation requires the attacker to possess authenticated access to at least one valid tenant within the targeted SuperTokens Core instance. The root cause stems from insufficient contextual validation and boundary enforcement during inter-tenant request processing, allowing cross-tenant data access without triggering proper authorization failures.",
  "technicalDetails": "The vulnerability resides within the SuperTokens Inc. SuperTokens Core component across versions v6.0.0 through v11.4.0. Specifically, the core authentication and session management logic fails to adequately enforce boundary isolation and tenant context separation during API request routing and internal data retrieval operations.\nThe root cause is an inadequate tenant validation mechanism within the application logic, which fails to restrict scoped session queries and endpoint handlers to the authenticated caller's designated tenant identifier. Consequently, when an authenticated user crafts requests targeting endpoints or session stores, the system does not properly validate whether the requested resource context matches the caller's authorized tenant boundaries.\nThe attack flow proceeds as follows: First, an attacker establishes a legitimate authenticated session within a compromised or attacker-controlled tenant on the target SuperTokens Core instance. Armed with valid session credentials, the attacker crafts arbitrary HTTP requests directed at application endpoints or data retrieval routines associated with SuperTokens Core. By manipulating tenant identification parameters, headers, or context structures within the request, the attacker bypasses logical access controls.\nBecause the vulnerable component fails to enforce strict tenant isolation, the SuperTokens Core backend processes the request against global or cross-tenant scopes rather than restricting the operation to the caller's specific tenant namespace. This payload behavior allows the attacker to read session data, query sensitive records, and interact with API endpoints designated for completely isolated tenants.\nNetwork exposure includes any deployment of SuperTokens Core exposing its API endpoints to authenticated clients across multiple tenants. The privilege requirement is limited to authenticated status within any single valid tenant, requiring no elevated administrative privileges. Post-exploitation impact encompasses total compromise of multi-tenant confidentiality and data integrity, enabling unauthorized data exfiltration and session hijacking across tenant domains."
}
CVE-2026-37171: SuperTokens Core Tenant Separation Vulnerability (MEDIUM Severity, CVSS: 5.9) - Sceawere