Authentication Bypass Vulnerability in Auth0 Symfony SDK
CVE-2026-50157

6.5MEDIUM

Key Information:

Vendor

Auth0

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-50157?

The Auth0 Symfony SDK permits the acceptance of OAuth 2.0 bearer access tokens through both the token URL query parameter and the Authorization header, posing a security risk. This dual acceptance can lead to exposure of tokens in server logs, browser history, or referrer data, making them susceptible to replay attacks against protected API endpoints. This vulnerability affects versions from 5.0.0-BETA0 up to 5.9.0 and has been resolved in version 5.9.0.

Affected Version(s)

symfony >= 5.0.0-BETA0, < 5.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.