PT-2026-29313 · Scitokens · Scitokens

Pmcao

·

Published

2026-03-31

·

Updated

2026-04-02

·

CVE-2026-32726

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SciTokens C++ versions prior to 1.4.1
Description The SciTokens C++ library, used for creating and utilizing SciTokens, contains a flaw in its path-based scope validation. The enforcer performs a string-prefix comparison to verify if a requested resource path is within a token's authorized scope. This check lacks path-segment boundary enforcement, allowing a token scoped to one path to incorrectly authorize access to sibling paths sharing the same prefix.
Recommendations Update to version 1.4.1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32726
GHSA-Q5FM-FGVX-32JQ

Affected Products

Scitokens