Executive brief
The Auth0 AD/LDAP Connector is a bridge that integrates Active Directory systems with Auth0's identity platform. Versions 6.5.0 and earlier expose an unprotected administrative panel on the local system that allows any local user to access management functions without authentication, potentially exposing plaintext Active Directory service account credentials and enabling configuration tampering.
Technical details
The vulnerability is a missing authentication flaw (CWE-306) in the administrative panel of the Auth0 AD/LDAP Connector. The panel listens on the local loopback interface without enforcing authentication, allowing any local process or low-privileged user on the host system to access sensitive management endpoints. An attacker with local access can read configuration details including plaintext Active Directory credentials and modify connector settings. The attack vector is local only; remote exploitation is not possible. The fix is to upgrade to version 8.0.0 or later.
Affected products
- Auth0 AD/LDAP Connector 6.5.0 and earlier
Timeline
- 2026-09-08: disclosed