Stored Cross-Site Scripting Vulnerability in Auth0 AD/LDAP Connector
CVE-2026-85982

9CRITICAL

Key Information:

Vendor

Auth0

Vendor
CVE Published:
8 September 2026

What is CVE-2026-85982?

The Auth0 AD/LDAP Connector is susceptible to stored Cross-Site Scripting (XSS) vulnerabilities. This arises from inadequate HTML encoding of data within search results and updater log content that is presented in the admin panel. An authenticated user possessing the rights to amend directory attributes, or even a low-privileged local user on the system hosting the connector, can embed malicious script content. If an administrator subsequently views the compromised search results or update logs, the injected script may execute in their browser, posing a significant threat to the application's integrity and the security of its users.

Affected Version(s)

Auth0 AD/LDAP Connector 0 <= 6.5.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.