CVE-2025-68129
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK versions between v8.0.0 and v8.17.0, or applications using the following SDKs that rely on the Auth0-PHP SDK versions between v8.0.0 and v8.17.0: Auth0/symfony versions between 5.0.0 and 5.5.0, Auth0/laravel-auth0 versions between 7.0.0 and 7.19.0, and/or Auth0/wordpress plugin versions between 5.0.0-BETA0 and 5.4.0. Auth0/Auth0-PHP version 8.18.0 contains a patch for the issue.
Published:Dec 17, 2025
Last Modified:Mar 5, 2026
EPS:Dec 17, 2025
EPSS Score:0.00112
CVSS Score:6.8
Affected Products
Vendor
Product
Action
Vendor
Auth0
Product
Auth0-php
Auth0
Auth0-php
Vendor
Auth0
Product
Laravel-auth0
Auth0
Laravel-auth0
Vendor
Auth0
Product
Symfony
Auth0
Symfony
Vendor
Auth0
Product
Wp-auth0
Auth0
Wp-auth0
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
