Executive brief
The Auth0 AD/LDAP Connector contains a stored cross-site scripting vulnerability in its admin panel that displays search results and update logs. An authenticated attacker with directory modification privileges—or a low-privileged local user on the connector host—can inject malicious scripts that execute when administrators view these panels. This allows attackers to compromise administrator accounts and gain unauthorized access to Auth0's identity management systems.
Technical details
The vulnerability is a stored cross-site scripting (CWE-79) issue caused by improper HTML encoding of user-controlled data displayed in the Auth0 AD/LDAP Connector admin panel. An attacker with authenticated access to modify directory attributes (or local system access to the connector host) can inject script content into searchable fields or update logs. When an administrator later views the affected search results or update logs, the unencoded script executes in their browser with the admin's privileges. The attack requires prior authentication and user interaction (admin viewing the panel). Patches are available in version 8.0.0 and later.
Affected products
- Auth0 AD/LDAP Connector before 8.0.0
Timeline
- 2026-09-08: disclosed