CVE-2026-84685 Details
Description
The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. Under the listed preconditions, tokens cached in module memory can be retrieved across subsequent requests processed by the same server runtime.
A vulnerability exists in the Auth0 React Native SDK's web platform implementation, specifically in versions 5.0.0 through 5.11.0. The issue arises in server-side rendering (SSR) environments where module state persists across HTTP requests. In these conditions, the SDK's in-memory token cache is not scoped to individual user sessions, allowing tokens cached in module memory to be accessed across subsequent requests processed by the same server runtime.
Users can upgrade to Auth0 React Native SDK version 5.11.1 or greater to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://trust.okta.com/security-advisories/improper-cache-isolation-in-auth0-react-native-auth0-sdk-web-platform-credential-management-cve-2026-84685 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-488 | Exposure of Data Element to Wrong Session | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Okta react-native-auth0 | >= 5.0.0, <= 5.11.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion