Impact
The Auth0 AD/LDAP Connector's administrative panel is exposed on the local loopback interface, and it does not require authentication for access in versions 6.5.0 and earlier. A local user with only low privileges can hit the panel's endpoints, read the connector configuration, and even modify settings. Because the configuration contains plaintext Active Directory service account credentials, an attacker can obtain privileged credentials that enable further compromise of the AD domain.
Affected Systems
Auth0 AD/LDAP Connector versions 6.5.0 and all earlier releases are affected. The product is provided by Auth0. No later releases are impacted in the known data.
Risk and Exploitability
The CVSS base score of 6.7 indicates moderate severity; the vulnerability is exploitable only from the host itself, requiring local user or process access. The EPSS score is not available, so there is no public data on exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. An attacker who can run a low‑privileged process on the host can read credentials and change settings, but cannot spread beyond the host through this asset alone.
OpenCVE Enrichment