What is CVE-2026-37171?
This vulnerability involves a lack of tenant separation in SuperTokens Core versions v6.0.0 to v11.4.0. It allows an authenticated user in one tenant to access sessions, data, and endpoints belonging to another tenant. Immediate upgrade of affected versions is strongly recommended.
Azərbaycanca: Bu zəiflik SuperTokens Core-un v6.0.0-dan v11.4.0-a qədər versiyalarında tenant ayrımının olmaması ilə bağlıdır. Bir tenant-da autentifikasiya olunmuş istifadəçiyə digər tenant-ların sessiyalarına, məlumatlarına və endpoint-lərinə giriş imkanı verir. Dərhal təsirlənən versiyaları yeniləmək tövsiyə olunur.
FAQ2
Which versions of SuperTokens Core are affected by CVE-2026-37171?
This vulnerability affects SuperTokens Core versions v6.0.0 to v11.4.0.
What does CVE-2026-37171 allow an authenticated user to do?
It allows an authenticated user in one tenant to access sessions, data, and endpoints belonging to another tenant.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.