CVE-2026-85983
Awaiting Analysis Awaiting Analysis - Queue

Auth0 AD/LDAP Connector Configuration Code Execution

Vulnerability report for CVE-2026-85983, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: Okta

Description

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
auth0 adldap_connector *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Auth0 AD/LDAP Connector has a flaw where a low-privileged user on the host system can modify its configuration during startup. This modified configuration can lead to arbitrary code execution with the privileges of the service account when the service restarts.

Impact Analysis

An attacker with low privileges could escalate their access to execute code with higher privileges, potentially compromising the system or accessing sensitive data processed by the connector.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements such as GDPR (data protection) or HIPAA (health information security), potentially resulting in legal penalties or reputational damage.

Mitigation Strategies

Restrict low-privileged users from modifying the Auth0 AD/LDAP Connector configuration files. Ensure the service account has minimal necessary permissions and monitor for unauthorized configuration changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85983. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart