Impact
SuperTokens Core versions 6.0.0 through 11.4.0 lack proper tenant separation, allowing an authenticated user in one tenant to view and use sessions, data, and API endpoints belonging to another tenant. This results in the disclosure, modification, or execution of activities on data that the user should not be authorized to manipulate, constituting an authorization weakness (CWE‑863).
Affected Systems
SuperTokens Inc. SuperTokens Core, affected from v6.0.0 to v11.4.0.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate impact. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an authenticated user within a tenant exploiting the missing isolation to access resources of a separate tenant. Exploitation requires only valid authentication within the vulnerable tenant and no additional conditions are described.
OpenCVE Enrichment