CVE-2018-6873: AUTH0 AUTH0.JS

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

Affected products

  • AUTH0 AUTH0.JS: up to and including 8.10.1

Published 2018-04-04. Last modified 2026-06-17.