Junglewise Threat Intelligence

CVE-2026-85981: Auth0 AD/LDAP Connector unauthenticated admin panel

CVE-2026-85981 · Severity: medium · CVSS 6.7 · Published 2026-09-08

Technologies: Auth0 AD/LDAP Connector. Vendors: Auth0.

Executive brief

The Auth0 AD/LDAP Connector is a bridge that integrates Active Directory systems with Auth0's identity platform. Versions 6.5.0 and earlier expose an unprotected administrative panel on the local system that allows any local user to access management functions without authentication, potentially exposing plaintext Active Directory service account credentials and enabling configuration tampering.

Technical details

The vulnerability is a missing authentication flaw (CWE-306) in the administrative panel of the Auth0 AD/LDAP Connector. The panel listens on the local loopback interface without enforcing authentication, allowing any local process or low-privileged user on the host system to access sensitive management endpoints. An attacker with local access can read configuration details including plaintext Active Directory credentials and modify connector settings. The attack vector is local only; remote exploitation is not possible. The fix is to upgrade to version 8.0.0 or later.

Affected products

  • Auth0 AD/LDAP Connector 6.5.0 and earlier

Timeline

  • 2026-09-08: disclosed

References

Related threats