๐Ÿ” CVE Alert

CVE-2026-85981

MEDIUM 6.7

Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector

CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.

CWE CWE-306
Vendor auth0
Product auth0 ad/ldap connector
Published Sep 8, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for auth0 auth0 ad/ldap connector

Be the first to know when new medium vulnerabilities affecting auth0 auth0 ad/ldap connector are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Auth0 / Auth0 AD/LDAP Connector
0 โ‰ค 6.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
trust.okta.com: https://trust.okta.com/security-advisories/unauthenticated-localhost-admin-panel-in-auth0-ad-ldap-connector-cve-2026-85981