CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6921

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)

CVE-2026-37171 is a cross-tenant authorization flaw in SuperTokens Core versions 6.0.0 through 11.4.0 that allows improper session isolation between tenants. The vulnerability stems from insufficient tenant separation in session operations, classified under CWE-863 (Incorrect Authorization). Organizations running affected versions face exposure to unauthorized cross-tenant access.

Why it matters: Teams deploying SuperTokens Core for multi-tenant authentication must upgrade immediately, as an attacker can potentially access sessions and data across tenant boundaries.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary