๐Ÿ” CVE Alert

CVE-2026-32716

HIGH 8.1

SciTokens: Authorization Bypass via Incorrect Scope Path Prefix Checking

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
7th

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using a simple prefix match (startswith). This allows a token with access to a specific path (e.g., /john) to also access sibling paths that start with the same prefix (e.g., /johnathan, /johnny), which is an Authorization Bypass. This issue has been patched in version 1.9.6.

CWE CWE-285
Vendor scitokens
Product scitokens
Published Mar 31, 2026
Last Updated Mar 31, 2026
Stay Ahead of the Next One

Get instant alerts for scitokens scitokens

Be the first to know when new high vulnerabilities affecting scitokens scitokens are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

scitokens / scitokens
< 1.9.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/scitokens/scitokens/security/advisories/GHSA-w8fp-g9rh-34jh github.com: https://github.com/scitokens/scitokens/commit/7a237c0f642efb9e8c36ac564b745895cca83583 github.com: https://github.com/scitokens/scitokens/releases/tag/v1.9.6