TopVuln

High-risk vulnerability digests

CVE-2026-32714

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-03-31 03:15:55
EPSS
<0.1% probability · 2.3th percentile — 2026-05-05
Affected versions
SciTokens all versions prior to 1.9.6
Summary
This vulnerability allows attackers to execute arbitrary SQL commands against the local SQLite database used by the SciTokens KeyCache class. It occurs because unsafe string formatting is used to construct SQL queries with untrusted user input.
Remediation
Upgrade SciTokens to version 1.9.6 or later to patch this vulnerability. Restrict access to the SciTokens service to trusted users only if an immediate upgrade cannot be completed.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.