PT-2026-29184 · Scitokens · Scitokens

Pmcao

·

Published

2026-03-31

·

Updated

2026-04-04

·

CVE-2026-32716

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SciTokens versions prior to 1.9.6
Description SciTokens is a library for generating and using SciTokens. The Enforcer component incorrectly validates scope paths using a simple prefix match, allowing a token with access to a specific path to also access sibling paths that share the same prefix. This results in an Authorization Bypass. The issue occurs because the startswith method is used for scope path validation, which is insufficient for secure access control. The vulnerable component is the Enforcer.
Recommendations Update to SciTokens version 1.9.6 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32716
GHSA-W8FP-G9RH-34JH
OPENSUSE-SU-2026:10491-1

Affected Products

Scitokens