CVE-2026-37171

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

Published 2026-08-07. Last modified 2026-09-09.