PT-2026-29184 · Scitokens · Scitokens
Pmcao
·
Published
2026-03-31
·
Updated
2026-04-04
·
CVE-2026-32716
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SciTokens versions prior to 1.9.6
Description
SciTokens is a library for generating and using SciTokens. The Enforcer component incorrectly validates scope paths using a simple prefix match, allowing a token with access to a specific path to also access sibling paths that share the same prefix. This results in an Authorization Bypass. The issue occurs because the
startswith method is used for scope path validation, which is insufficient for secure access control. The vulnerable component is the Enforcer.Recommendations
Update to SciTokens version 1.9.6 or later.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scitokens