CVE-2026-34236 Details
Description
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies. This issue has been patched in version 8.19.0.
A vulnerability exists in the Auth0-PHP SDK for Auth0 Authentication and Management APIs, affecting versions 8.0.0 prior to 8.19.0. The issue arises because cookies are encrypted with inadequate entropy, potentially allowing threat actors to brute-force the encryption key and forge session cookies. This vulnerability is also present in applications using the Auth0-PHP SDK's dependent SDKs: Auth0/symfony, Auth0/laravel0-auth0, or Auth0/wordpress.
Users can upgrade to Auth0-PHP version 8.19.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/auth0/auth0-PHP/releases/tag/8.19.0 | [email protected] | ProductRelease Notes |
| https://github.com/auth0/auth0-PHP/security/advisories/GHSA-w3wc-44p4-m4j7 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-331 | Insufficient Entropy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| auth0 auth0-php | >= 8.0.0, < 8.19.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |