CVE-2025-68129
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK versions between v8.0.0 and v8.17.0, or applications using the following SDKs that rely on the Auth0-PHP SDK versions between v8.0.0 and v8.17.0: Auth0/symfony versions between 5.0.0 and 5.5.0, Auth0/laravel-auth0 versions between 7.0.0 and 7.19.0, and/or Auth0/wordpress plugin versions between 5.0.0-BETA0 and 5.4.0. Auth0/Auth0-PHP version 8.18.0 contains a patch for the issue.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.43%
- Percentil entre todas las CVEs puntuadas: 35
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access85 % - Impacto secundario
T1552.007Container APIcredential access70 %
Red sin privilegios, validación impropia de tokens que permite usar ID tokens como access tokens (CWE-863: acceso impropio). Impacto: acceso con identidad falsa (T1078) y exposición de credenciales en tokens (T1552.007).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (4)
CWE
- CWE-863
Referencias
- https://github.com/auth0/auth0-PHP/commit/7fe700053aee609718460c123f00f53c511f0f7f
- https://github.com/auth0/auth0-PHP/releases/tag/8.18.0
- https://github.com/auth0/auth0-PHP/security/advisories/GHSA-j2vm-wrq3-f7gf
- https://github.com/auth0/laravel-auth0/commit/a1c3344dc0e5a36e8f56c8cfc535728d3d7558f3
- https://github.com/auth0/laravel-auth0/releases/tag/7.20.0
- https://github.com/auth0/laravel-auth0/security/advisories/GHSA-7hh9-gp72-wh7h
- https://github.com/auth0/symfony/commit/0103d6f8dcef6996653fad1f823d1c167f472479
- https://github.com/auth0/symfony/releases/tag/5.6.0
- https://github.com/auth0/symfony/security/advisories/GHSA-f3r2-88mq-9v4g
- https://github.com/auth0/wordpress/commit/b207c6f7fd06507b90c4e6bcc18a857ef9e018de
- https://github.com/auth0/wordpress/releases/tag/5.5.0
- https://github.com/auth0/wordpress/security/advisories/GHSA-vvg7-8rmq-92g7
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-68129",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-68129",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-12-18T14:53:59.445866Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "auth0",
"product": "auth0-PHP",
"versions": [
{
"status": "affected",
"version": ">= 8.0.0, < 8.18.0"
}
]
}
]
}
],
"published": "2025-12-17T22:16:01.713",
"references": [
{
"url": "https://github.com/auth0/auth0-PHP/commit/7fe700053aee609718460c123f00f53c511f0f7f",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/auth0-PHP/releases/tag/8.18.0",
"tags": [
"Product",
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/auth0-PHP/security/advisories/GHSA-j2vm-wrq3-f7gf",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/laravel-auth0/commit/a1c3344dc0e5a36e8f56c8cfc535728d3d7558f3",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/laravel-auth0/releases/tag/7.20.0",
"tags": [
"Product",
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/laravel-auth0/security/advisories/GHSA-7hh9-gp72-wh7h",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/symfony/commit/0103d6f8dcef6996653fad1f823d1c167f472479",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/symfony/releases/tag/5.6.0",
"tags": [
"Product",
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/symfony/security/advisories/GHSA-f3r2-88mq-9v4g",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/wordpress/commit/b207c6f7fd06507b90c4e6bcc18a857ef9e018de",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/wordpress/releases/tag/5.5.0",
"tags": [
"Product",
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/wordpress/security/advisories/GHSA-vvg7-8rmq-92g7",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK versions between v8.0.0 and v8.17.0, or applications using the following SDKs that rely on the Auth0-PHP SDK versions between v8.0.0 and v8.17.0: Auth0/symfony versions between 5.0.0 and 5.5.0, Auth0/laravel-auth0 versions between 7.0.0 and 7.19.0, and/or Auth0/wordpress plugin versions between 5.0.0-BETA0 and 5.4.0. Auth0/Auth0-PHP version 8.18.0 contains a patch for the issue."
},
{
"lang": "es",
"value": "Auth0-PHP es un SDK de PHP para las API de autenticación y gestión de Auth0. En aplicaciones construidas con el SDK de Auth0-PHP, la validación de audiencia en los tokens de acceso se realiza de forma incorrecta. Sin una validación adecuada, las aplicaciones afectadas pueden aceptar tokens de ID como tokens de acceso. Los proyectos se ven afectados si utilizan versiones del SDK de Auth0-PHP entre v8.0.0 y v8.17.0, o aplicaciones que utilizan los siguientes SDK que dependen de las versiones del SDK de Auth0-PHP entre v8.0.0 y v8.17.0: versiones de Auth0/symfony entre 5.0.0 y 5.5.0, versiones de Auth0/laravel-auth0 entre 7.0.0 y 7.19.0, y/o versiones del plugin de WordPress de Auth0 entre 5.0.0-BETA0 y 5.4.0. La versión 8.18.0 de Auth0/Auth0-PHP contiene un parche para el problema."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:auth0:auth0-php:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12378349-3A0C-4E82-9568-C0B4B775F1F4",
"versionEndExcluding": "8.18.0",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:auth0:laravel-auth0:*:*:*:*:*:laravel:*:*",
"vulnerable": true,
"matchCriteriaId": "01BEB1D0-CD7D-4223-ADC3-7DB8DB852867",
"versionEndExcluding": "7.20.0",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:auth0:symfony:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1093AE14-FD36-4E4D-983E-48D4CCE77D49",
"versionEndExcluding": "5.6.0",
"versionStartIncluding": "5.0.0"
},
{
"criteria": "cpe:2.3:a:auth0:wp-auth0:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "1C6C5FAD-40FC-4715-B4C1-419EC9AC51FB",
"versionEndExcluding": "5.5.0",
"versionStartIncluding": "5.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}