CVE-2026-32714Disclosure(scitokens / scitokens_library)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch scitokens scitokens_library systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to construct SQL queries with user-supplied data (such as issuer and key_id). This allowed an attacker to execute arbitrary SQL commands against the local SQLite database. This issue has been patched in version 1.9.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • scitokens_library

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 6 mentions (2026-03-31); latest day: 2
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
scitokens_library

Deep dive

Activity timeline8 mentions / 2d
02356Mentions · 2026-03-31: 6Mentions · 2026-04-01: 2Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 5Technical Details · 2026-04-01: 203-3104-01
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-316
Disclosure4General1Patch1
2026-04-012
Disclosure2
Full discourse8 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-5128 | CVSS 10.0 🔴 CVE-2026-3300 | CVSS 9.8 🔴 CVE-2026-32714 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post merely lists three high‑CVSS top vulnerabilities with scores and a website link, lacking details on exploitation, patching, or prioritization.

    0001037
    5.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `SciTokens` is vulnerable to a critical SQL Injection (CVE-2026-32714) in its KeyCache component, allowing unauthorized database access. Monitor for updates. #SQLi #SciTokens #InfoSec https://www.pulsepatch.io/posts/cve-2026-32714-scitokens-sql-injection

    Post summary

    The note announces a critical SQL injection vulnerability (CVE-2026-32714) in SciTokens' KeyCache component, links to a PulsePatch post for details, but does not mention exploits, active use, or a patch.

    0000038
    6 followersView on X
  • CosmicBytez@CosmicBytez
    Disclosure

    Security Advisory: CVE-2026-32714: Critical SQL Injection in SciTokens KeyCache (CVSS 9.8) https://labs.cosmicbytez.ca/security/cve-2026-32714 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The advisory announces CVE-2026-32714, a critical SQL injection vulnerability in SciTokens KeyCache with a CVSS score of 9.8, but does not include proof of concept, exploitation evidence, or mitigation guidance.

    0000040
    1 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-32714 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32714 #CVE-2026-32714 #CVE #Critical #CyberSecurity #InfoSec https://t.co/l99hZ3mGvV

    Post summary

    The tweet announces CVE-2026-32714, noting its critical severity and linking to the NVD entry, but includes no additional technical, exploit, or mitigation information.

    0000027
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32714 SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because i… https://www.cve.org/CVERecord?id=CVE-2026-32714

    Post summary

    The post provides a brief disclosure of an SQL Injection vulnerability in the SciTokens KeyCache class, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000084
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32714 - Critical SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.f... https://www.thehackerwire.com/vulnerability/CVE-2026-32714/ https://t.co/Sx3PbZAlRH

    Post summary

    The post announces CVE-2026-32714, a critical SQL injection flaw in SciTokens' KeyCache class before v1.9.6, with no mention of PoC, exploit, or patch.

    0000060
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32714: CRITICAL] Learn about Cyber Security: SciTokens library fixed SQL Injection vulnerability in KeyCache class, enhancing protection in version 1.9.6. Update now for improved security.#cve,CVE-2026-32714,#cybersecurity https://cvefind.com/CVE-2026-32714

    Post summary

    The notice announces that SciTokens library version 1.9.6 patches a critical SQL injection flaw, urging users to update.

    0000059
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32714: SciTokens vulnerable to SQL Inje... str.format() SQL injection in SciTokens KeyCache lets attackers dump/modify the entire SQLite DB through malicious issu... https://zerodaysignal.com/vulnerability/CVE-2026-32714 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑32714, detailing a SQL injection flaw in SciTokens KeyCache that could allow full database compromise, without mentioning PoC, exploit, or patch information.

    0000081
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appscitokensscitokens_library---

Explore more