Unauthorized Access in Auth0 AD/LDAP Connector Affects Local Administration
CVE-2026-85981
6.7MEDIUM
What is CVE-2026-85981?
A serious security flaw in the Auth0 AD/LDAP Connector, specifically versions 6.5.0 and earlier, arises from the administrative panel listening on the local loopback interface without requiring authentication. This weakness potentially allows a local user or process to access management endpoints without credentials. Such access can expose sensitive configuration details, including plaintext Active Directory service account credentials, and enables unauthorized modification of connector settings, elevating the risk of further exploitations within the system.
Affected Version(s)
Auth0 AD/LDAP Connector 0 <= 6.5.0
