


Perceptive Security
SOC/SIEM Consultancy

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 16:03:27
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Auth0.js client-side JavaScript library contains a vulnerability in versions 8.11.0 to 9.32.0 where the SDK may improperly return user profile information when provided with a valid access token and a specifically crafted invalid ID token. This authentication bypass vulnerability allows unauthorized access to user profile data under specific preconditions. The vulnerability has been patched in version 10.0.0. Organizations using affected versions should upgrade immediately to prevent potential unauthorized data exposure.
Technical details
Mitigation steps:
Affected products:
Auth0.js
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42280
https://github.com/auth0/auth0.js/security/advisories/GHSA-8qjv-jj2q-x832
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
