CVE-2026-85981

MEDIUM CVSS 3.1: 6.7 EPSS 0.18%
Updated Sep 10, 2026
Auth0
Parameter Value
CVSS 6.7 (MEDIUM)
Type CWE-306 (Missing Authentication for Critical Function)
Vendor Auth0
Public PoC No

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1