s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-42280

📛 CVE Title

(no title)

Description

Auth.js SDK has Improper Permission Checking

Description (MITRE) cveawg.mitre.org

Pulled from cveawg.mitre.org/api/cve/CVE-2026-42280 on 2026-07-28. Shown when MITRE's text differs from the cvelistV5 mirror.

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is fixed in 10.0.0.

Overview

State
Assigner (CNA)
CVSS severity
high
CVSS score
CVSS 7.1 / 10 7.1 7.1 / 10
CVSS vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Effective score
7.1 / 10 HIGH source: CNA overview
CWE(s)
Reserved
Published
Last updated
Source
https://www.tenable.com/cve/CVE-2026-42280
Linked Threat
CVE-2026-42280 — CVE-2026-42280

NVD / KEV / EPSS data refreshed 2026-05-24 23:55 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-32533

EUVD enrichment is queued; refresh the page in a few seconds.

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

Web references (4)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Remediations (10)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-42280.json.

Not stored.