


Perceptive Security
SOC/SIEM Consultancy

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypas…
Published:
30 March 2026 at 22:00:00
Alert date:
31 March 2026 at 19:02:07
Source:
nvd.nist.gov
Identity & Access, Supply Chain & Dependencies
SciTokens C++ library prior to version 1.4.1 contains an authorization bypass vulnerability in path-based scope validation. The vulnerability stems from improper string-prefix comparison that doesn't require path-segment boundaries, allowing tokens scoped to one path to incorrectly authorize access to sibling paths with the same prefix. This could lead to unauthorized access to resources beyond the intended scope. The issue affects the enforcer component's validation logic and has been patched in version 1.4.1. Organizations using affected versions should upgrade immediately to prevent potential unauthorized access.
Technical details
Mitigation steps:
Affected products:
SciTokens C++
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32726
https://github.com/scitokens/scitokens-cpp/commit/decfe2f00cb9cabbf1e17a3bb2cd4ea1bbbd8a73
https://github.com/scitokens/scitokens-cpp/security/advisories/GHSA-q5fm-fgvx-32jq
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
