


Perceptive Security
SOC/SIEM Consultancy

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using a simple pr…
Published:
30 maart 2026 om 22:00:00
Alert date:
31 maart 2026 om 04:03:55
Source:
nvd.nist.gov
Identity & Access, Supply Chain & Dependencies
SciTokens reference library prior to version 1.9.6 contains an authorization bypass vulnerability in the Enforcer component. The vulnerability stems from incorrect scope path validation using simple prefix matching with startswith function. This allows tokens with access to specific paths to also access sibling paths that share the same prefix, effectively bypassing intended authorization controls. For example, a token granted access to /john could also access /johnathan or /johnny paths. The issue has been addressed and patched in SciTokens version 1.9.6.
Technical details
Mitigation steps:
Affected products:
SciTokens
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32716
https://github.com/scitokens/scitokens/commit/7a237c0f642efb9e8c36ac564b745895cca83583
https://github.com/scitokens/scitokens/releases/tag/v1.9.6
https://github.com/scitokens/scitokens/security/advisories/GHSA-w8fp-g9rh-34jh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
