PatchSiren

SuperTokens Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM SuperTokens Inc. CVE published 2026-08-07

CVE-2026-37171

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T14:16:59.237Z and has not been modified since then. This vulnerability affects SuperTokens Core versions between v6.0.0 and v11.4.0, allowing an authenticated party in one tenant to access sessions, data, and endpoints of another tenant due to a lack of tenant separation. Administrators and users [truncated]