HomepageOkta logo

Local Privilege Escalation in Auth0 AD/LDAP Connector CVE-2026-85983 - Sep 8, 2026

View all security advisories

Description

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.

Preconditions

  1. An authenticated, low-privileged user must have local access to the host system where the Auth0 AD/LDAP Connector is installed.

Fix

Upgrade the auth0/ad-ldap-connector to version 8.00 or greater.

CVE details

CVE ID

CVE-2026-85983

Published Date

2026-09-08

Vulnerability Type

Code Injection / Local Privilege Escalation

CWE

CWE-94 – Improper Control of Generation of Code

CVSS v3

Score: 7.8

Vector string: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Local Privilege Escalation in Auth0 AD/LDAP Connector