SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85983

HIGH · CVSS 7.8 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Auth0 AD/LDAP Connector is vulnerable due to improper handling of configuration values during startup, allowing low-privileged users to alter its settings. This misconfiguration can lead to arbitrary code execution with the privileges of the service account upon service restart. Organizations utilizing this connector should prioritize remediation to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85983
Severity
HIGH
CVSS
7.8
EPSS
0.14%

Original NVD Description

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.