
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32716 is an authorization bypass vulnerability in the SciTokens reference library caused by incorrect scope path prefix checking in the Enforcer component. Prior to version 1.9.6, the library uses a simple Python startswith() call to validate scope paths, allowing a token authorized for /john to also access sibling paths such as /johnathan or /johnny. The vulnerability affects all versions of the scitokens pip package before 1.9.6 and was disclosed on March 30–31, 2026. It carries a CVSS v3.1 base score of 8.1 (High) per the GitHub Security Advisory, or 6.5 (Medium) per NVD scoring (Github Advisory, Red Hat Advisory).
The root cause is improper authorization logic (CWE-285) in src/scitokens/scitokens.py, specifically in the _validate_scp and _validate_scope methods. Both methods use norm_requested_path.startswith(norm_path) to determine whether a requested path falls within the token's authorized scope, without verifying that the match occurs at a path boundary (i.e., followed by / or end-of-string). The fix introduced a new static method _scope_path_matches() that correctly checks for exact match, trailing-slash prefix, or path-separator-bounded prefix before granting access. Exploitation requires a valid SciToken with low-privilege access to any path whose name is a prefix of another path on the same system (Github Advisory, Patch Commit).
An authenticated user holding a valid SciToken scoped to a specific path can read or write to unintended sibling paths that share the same string prefix. In shared storage environments where top-level directories correspond to usernames or project identifiers, this could allow one user to access another user's data — for example, a user with a token for /john could access /johnathan's files. The confidentiality and integrity impacts are both rated High, while availability is unaffected (Github Advisory).
A proof-of-concept (PoC) script is publicly available in the GitHub Security Advisory, but it only demonstrates the bug locally by instantiating the library and calling its methods — it does not interact with any external system or network target. There is no confirmed in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.015% (4th percentile), indicating a low near-term exploitation probability (Github Advisory, Github Advisory).
read:/john or write:/john./johnathan, /johnny).GET /johnathan/sensitive_file).Enforcer evaluates '/johnathan'.startswith('/john') as True and grants access, allowing the attacker to read or write data in the unintended path (Github Advisory).scope: read:/john) successfully accessing a different, prefix-sharing path (e.g., /johnathan or /johnny) on the resource server.scope or scp claims containing short path values (e.g., /jo, /a) that could match a large number of sibling paths — potentially indicating deliberate abuse of the prefix-matching flaw.Upgrade the scitokens Python package to version 1.9.6 or later, which replaces the flawed startswith() check with a proper _scope_path_matches() method that enforces path boundary semantics. No configuration-based workaround is available for the library itself; the fix must be applied at the code level. After patching, administrators should audit access logs to identify any unauthorized cross-path access that may have occurred prior to the upgrade (Github Advisory, Release v1.9.6).
The vulnerability was reported by researcher pmcao and patched by maintainer djw8605 (Derek Weitzel). Red Hat tracked the issue via Bugzilla (Bug 2453283) and rated it High severity. Brief social media mentions appeared on Mastodon and Bluesky shortly after disclosure, consistent with routine CVE notification activity rather than significant community concern (Red Hat Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."