The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade the Auth0 AD/LDAP Connector to version 7.0.0 or greater.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings. | |
| Title | Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Okta
Published:
Updated: 2026-09-08T20:17:06.765Z
Reserved: 2026-09-04T19:01:50.724Z
Link: CVE-2026-85981
No data.
Status : Received
Published: 2026-09-08T21:18:47.173
Modified: 2026-09-08T21:18:47.173
Link: CVE-2026-85981
No data.
OpenCVE Enrichment
Updated: 2026-09-09T09:30:08Z
Weaknesses