CVE-2026-32716
EUVD-2026-1729431.03.2026, 03:15
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using a simple prefix match (startswith). This allows a token with access to a specific path (e.g., /john) to also access sibling paths that start with the same prefix (e.g., /johnathan, /johnny), which is an Authorization Bypass. This issue has been patched in version 1.9.6.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| scitokens | scitokens_library | 𝑥 < 1.9.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration