THREATOPS
THREAT OPSThreat News › CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)

CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)

medoss_secPublished 2026-09-09

<p>Posted by Mr. Gatto on Sep 09</p>Hello,<br /> <br /> This is a disclosure for CVE-2026-37171, a cross-tenant authorization flaw<br /> in<br /> SuperTokens Core, the self-hosted authentication server by SuperTokens Inc.<br /> <br /> Affected: SuperTokens Core (supertokens-core) versions 6.0.0 through 11.4.0.<br /> CWE: CWE-863 (Incorrect Authorization).<br /> CVE: CVE-2026-37171 (published; NVD

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/692