Description
The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.
Published: 2026-09-08
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The Auth0 AD/LDAP Connector's administrative panel is exposed on the local loopback interface, and it does not require authentication for access in versions 6.5.0 and earlier. A local user with only low privileges can hit the panel's endpoints, read the connector configuration, and even modify settings. Because the configuration contains plaintext Active Directory service account credentials, an attacker can obtain privileged credentials that enable further compromise of the AD domain.

Affected Systems

Auth0 AD/LDAP Connector versions 6.5.0 and all earlier releases are affected. The product is provided by Auth0. No later releases are impacted in the known data.

Risk and Exploitability

The CVSS base score of 6.7 indicates moderate severity; the vulnerability is exploitable only from the host itself, requiring local user or process access. The EPSS score is not available, so there is no public data on exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. An attacker who can run a low‑privileged process on the host can read credentials and change settings, but cannot spread beyond the host through this asset alone.

Generated by OpenCVE AI on September 9, 2026 at 09:22 UTC.

Remediation

Vendor Solution

Upgrade the Auth0 AD/LDAP Connector to version 7.0.0 or greater.


OpenCVE Recommended Actions

  • Upgrade the Auth0 AD/LDAP Connector to version 7.0.0 or newer.
  • Run the connector under a restricted user account that has only the minimum necessary permissions for LDAP communication.
  • Configure the host firewall to block any external connections to the connector's admin port and monitor logs for unauthorized configuration changes.

Generated by OpenCVE AI on September 9, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Auth0
Auth0 ad/ldap Connector
Vendors & Products Auth0
Auth0 ad/ldap Connector

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.
Title Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Auth0 Ad/ldap Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:42:25.037Z

Reserved: 2026-09-04T19:01:50.724Z

Link: CVE-2026-85981

cve-icon Vulnrichment

Updated: 2026-09-10T14:42:21.317Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:18:47.173

Modified: 2026-09-10T15:17:49.807

Link: CVE-2026-85981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:42Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function