Skip to content
OktaOKTA-0HLWAI2

Improper Permission Checking in Auth0.js SDK CVE-2026-42280 - May 6, 2026

UnratedCVE-2026-42280 · Published May 6, 2026

Under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. Upgrade auth0/auth0.js to version 10.0.0 or greater.

Okta advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Okta advisories

All Okta
Advisory
Okta Access Gateway: code execution
Medium6.6Sep 8
Okta Access Gateway: code injection
Medium6.6Sep 8
Okta Privileged Access Client: command injection
Medium5.3Aug 25
Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK CVE-2026-50157 - Jun...
UnratedJun 10
Improper Proxy Cache Lookup in the Auth0 Next.js SDK CVE-2026-40155 - Apr 17, 2026
UnratedApr 17
Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1...
UnratedApr 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.