๐Ÿ” CVE Alert

CVE-2026-42280

HIGH 7.1

Improper Permission Checking in Auth.js SDK

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
9th

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is fixed in 10.0.0.

CWE CWE-863
Vendor auth0
Product auth0.js
Published May 27, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for auth0 auth0.js

Be the first to know when new high vulnerabilities affecting auth0 auth0.js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

auth0 / auth0.js
>= 8.11.0 , <= 9.32.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/auth0/auth0.js/security/advisories/GHSA-8qjv-jj2q-x832