OktaOKTA-0HLWAI2
Improper Permission Checking in Auth0.js SDK CVE-2026-42280 - May 6, 2026
UnratedCVE-2026-42280 · Published May 6, 2026
Under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. Upgrade auth0/auth0.js to version 10.0.0 or greater.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Okta Access Gateway: code execution | Medium6.6 | 2026.9.1 |
| Sep 8 | Okta Access Gateway: code injection | Medium6.6 | 2026.9.1 |
| Aug 25 | Okta Privileged Access Client: command injection | Medium5.3 | 1.111.1 |
| Jun 10 | Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK CVE-2026-50157 - Jun... | Unrated | No fix yet |
| Apr 17 | Improper Proxy Cache Lookup in the Auth0 Next.js SDK CVE-2026-40155 - Apr 17, 2026 | Unrated | No fix yet |
| Apr 1 | Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1... | Unrated | No fix yet |