CVE-2026-34236Disclosure(auth0 / auth0-php)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies. This issue has been patched in version 8.19.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-331

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • auth0-php

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
auth0-php

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-02: 1Mentions · 2026-04-08: 1Technical Details · 2026-04-02: 104-0204-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-34236: Auth0-PHP Cookie Encryption Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04b0FZ30

    Post summary

    The text refers to a security advisory for CVE‑2026‑34236, a cookie encryption flaw in Auth0‑PHP, outlining its business impact and general response guidance.

    0000031
    28 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34236 - High Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insu... https://www.thehackerwire.com/vulnerability/CVE-2026-34236/ https://t.co/wX37jWiu7t

    Post summary

    The tweet announces a high‑severity CVE‑2026‑34236 affecting Auth0 PHP SDK versions 8.0.0–8.18.9, where cookies are encrypted with insufficient protection, potentially allowing session manipulation.

    0000046
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appauth0auth0-php---

Explore more