Unauthorized Access in Auth0 AD/LDAP Connector Affects Local Administration
CVE-2026-85981

6.7MEDIUM

Key Information:

Vendor

Auth0

Vendor
CVE Published:
8 September 2026

What is CVE-2026-85981?

A serious security flaw in the Auth0 AD/LDAP Connector, specifically versions 6.5.0 and earlier, arises from the administrative panel listening on the local loopback interface without requiring authentication. This weakness potentially allows a local user or process to access management endpoints without credentials. Such access can expose sensitive configuration details, including plaintext Active Directory service account credentials, and enables unauthorized modification of connector settings, elevating the risk of further exploitations within the system.

Affected Version(s)

Auth0 AD/LDAP Connector 0 <= 6.5.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.