CVE-2026-85982
Awaiting Analysis Awaiting Analysis - Queue

Stored XSS in Auth0 AD/LDAP Connector

Vulnerability report for CVE-2026-85982, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: Okta

Description

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search results or update logs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
auth0 adldap_connector *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the Auth0 AD/LDAP Connector. It occurs because the application fails to properly encode HTML data in search results and updater logs displayed in the admin panel. An attacker with directory modification privileges or local host access can inject malicious scripts into these fields. When an administrator views the affected content, the script executes in their browser.

Detection Guidance

Detecting this vulnerability requires checking the Auth0 AD/LDAP Connector version and reviewing admin panel logs for suspicious script content in search results or updater logs. No specific commands are provided in the context.

Impact Analysis

If you are an administrator using the Auth0 AD/LDAP Connector, an attacker could steal your session cookies, perform actions on your behalf, or access sensitive data in the admin panel. If you are an attacker, you could gain unauthorized access to the system by tricking an administrator into viewing the malicious content.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations using this connector may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately upgrade the Auth0 AD/LDAP Connector to version 8.0.0 or higher to resolve the vulnerability. Ensure only trusted users have directory modification privileges and monitor admin panel logs for unauthorized script injections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85982. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart