Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2026-85982: Auth0 AD/LDAP Connector lets scripts run in admin browser
CVE-2026-85982 · published 1 month ago
Summary
The Auth0 AD/LDAP Connector does not properly filter HTML when showing search results and update logs in its admin panel. An attacker who can add or edit directory data, or someone with local access to the server, could place malicious script code that runs in an administrator’s browser when they view those pages. Apply the vendor’s update or patch and restrict who can modify directory attributes and access the connector host.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| auth0 | auth0 ad/ldap connector | <= 6.5.0 |
Original advisory text
Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search results or update logs.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published8 Sep 2026
Updated7 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta