CVE-2026-37171: Medium severity SuperTokens Inc. SuperTokens Core vulnerability
Published Aug 7, 2026
·Updated
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.
Affected Software
1 affected component
SuperTokens Inc. SuperTokens Core>=6.0.0<=11.4.0
Event History
Aug 7, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·02:16 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-37171?
CVE-2026-37171 has a medium severity rating of 5.9.
2
How does CVE-2026-37171 affect SuperTokens Core?
CVE-2026-37171 allows an authenticated user from one tenant to access sessions and data of another tenant within SuperTokens Core.
3
What versions of SuperTokens Core are impacted by CVE-2026-37171?
CVE-2026-37171 affects SuperTokens Core versions 6.0.0 to 11.4.0.
4
How do I fix CVE-2026-37171?
To mitigate CVE-2026-37171, ensure proper tenant separation is implemented in your SuperTokens Core deployment.
5
What is the risk level associated with CVE-2026-37171?
CVE-2026-37171 has a risk level of 42, indicating a notable vulnerability that needs attention.