SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85981

MEDIUM · CVSS 6.7 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) is vulnerable due to its exposure on the local loopback interface without authentication, allowing local, low-privileged users to access sensitive management endpoints. This could lead to unauthorized access to configuration details, including plaintext Active Directory service account credentials, and potential modification of connector settings. Organizations using this connector should prioritize patching to mitigate the risk of local exploitation by unauthorized users.

CVE
CVE-2026-85981
Severity
MEDIUM
CVSS
6.7
EPSS
0.12%

Original NVD Description

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.