CVE-2026-50157 | Auth0 Symfony up to 5.8.x Authorizer security authenticator supports token authentication replay
A vulnerability categorized as critical has been discovered in Auth0 Symfony up to 5.8.x. Impacted is the function Authorizer::authenticate/Authorizer::supports of the component Authorizer security authenticator. Such manipulation of the argument token leads to authentication bypass by capture-replay.
This vulnerability is listed as CVE-2026-50157. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More