Local Privilege Escalation in Auth0 AD/LDAP Connector CVE-2026-85983 - Sep 8, 2026
Description
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.
Preconditions
An authenticated, low-privileged user must have local access to the host system where the Auth0 AD/LDAP Connector is installed.
Fix
Upgrade the auth0/ad-ldap-connector to version 8.00 or greater.
CVE details
CVE ID | |
Published Date | 2026-09-08 |
Vulnerability Type | Code Injection / Local Privilege Escalation |
CWE | CWE-94 – Improper Control of Generation of Code |
CVSS v3 | Score: 7.8 Vector string: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |