OktaOKTA-02JA0JI
Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK CVE-2026-50157 - Jun...
UnratedCVE-2026-50157 · Published Jun 10, 2026
Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints. To remediate, upgrade auth0/symfony to version 5.9.0 or greater.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Okta Access Gateway: code execution | Medium6.6 | 2026.9.1 |
| Sep 8 | Okta Access Gateway: code injection | Medium6.6 | 2026.9.1 |
| Aug 25 | Okta Privileged Access Client: command injection | Medium5.3 | 1.111.1 |
| May 6 | Improper Permission Checking in Auth0.js SDK CVE-2026-42280 - May 6, 2026 | Unrated | No fix yet |
| Apr 17 | Improper Proxy Cache Lookup in the Auth0 Next.js SDK CVE-2026-40155 - Apr 17, 2026 | Unrated | No fix yet |
| Apr 1 | Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1... | Unrated | No fix yet |