« Back to list

Scitokens

Scitokens CPP Library: vulnerabilities and CVEs

Scitokens CPP Library has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-32726High (8.1)0.38%—Mar 31, 2026
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a…
CVE-2026-32725High (8.3)0.99%—Mar 31, 2026
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services2
  2. T1005 Data from Local System1
  3. T1078 Valid Accounts1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Scitokens