VulnSea

Auth0 has 6 CVEs on record between 2025 and 2026. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 7.1 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: Auth0 AD/LDAP Connector (3), node-jws (1), react-native-auth0 (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
5 prev 0

Products

  • Auth0 AD/LDAP Connector 3
  • node-jws 1
  • react-native-auth0 1
  • symfony 1
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Auth0 vulnerabilities

CVEs affecting Auth0, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-50157Medium· 6.5
1w ago

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bear…

Sunlitauth0 · symfonyEPSS 0.50%via NVD
CVE-2026-85983High· 7.8
2w ago

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configur…

TwilightAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.14%via NVD
CVE-2026-85982Critical· 9.0
2w ago

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to …

MidnightAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.22%via NVD
CVE-2026-85981Medium· 6.7
2w ago

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to acce…

SunlitAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.12%via NVD
CVE-2026-84685Medium· 6.5
2w ago

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. U…

SunlitAuth0 · react-native-auth0EPSS 0.18%via NVD
CVE-2025-65945High· 7.5PoC
9mo ago

auth0/node-jws is a JSON Web Signature implementation for Node.js

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditi…

Midnightauth0 · node-jwsEPSS 0.21%via NVD
Auth0 vulnerabilities (CVEs) · VulnSea