CVE-2026-85981
The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-306
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Auth0 Auth0 AD/LDAP Connector
Weakness type
Related vulnerabilities
- CVE-2026-79961 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-11838 — Improper Authorization in Yordam Informatics' Library Reservation System
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-86808 — moltis-org moltis vault.rs vault_recovery_handler missing authentication
- CVE-2026-73004 — Windows Autopilot Tampering Vulnerability
- CVE-2026-72964 — Windows Internet Connection Sharing (ICS) Tampering Vulnerability
- CVE-2026-69674 — Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability
- CVE-2026-69321 — Windows Power Dependency Coordinator Tampering Vulnerability