CVE-2026-50157
Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.50%
- CWE
- CWE-598
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- auth0 symfony
Weakness type
Related vulnerabilities
- CVE-2023-6014 — MLflow Authentication Bypass
- CVE-2021-36328 — Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may
- CVE-2020-5331 — RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session informatio
- CVE-2025-57800 — Audiobookshelf vulnerable to OIDC token exfiltration and account takeover
- CVE-2019-18573 — The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Ses
- CVE-2025-26473 — Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings
- CVE-2022-22551 — DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated a
- CVE-2021-21594 — Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerab