CVE-2026-32726 details an authorization bypass vulnerability in the SciTokens C++ library, affecting versions prior to 1.4.1. The flaw stems from a simple string-prefix comparison in path-based scope validation, allowing a token scoped to one path to incorrectly authorize access to sibling paths. Rated with a CVSS score of 8.1 (High), this vulnerability has a network attack vector and low attack complexity, potentially leading to high impact on confidentiality and integrity. There is currently no evidence of active exploitation, nor is public exploit code available, though the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.1CPE matchmatch criteria | cpe:2.3:a:scitokens:scitokens_cpp_library:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.