Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector
Summary
| CVE | CVE-2026-85982 |
|---|---|
| State | PUBLISHED |
| Assigner | Okta |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-08 21:18:47 UTC |
| Updated | 2026-09-10 15:17:49 UTC |
| Description | The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search results or update logs. |
Risk And Classification
Primary CVSS: v3.1 9 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS: 0.002190000 probability, percentile 0.123500000 (date 2026-09-10)
Problem Types: CWE-79 | CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Auth0 | Auth0 AD/LDAP Connector | affected 6.5.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| trust.okta.com/security-advisories/stored-cross-site-scripting-xss-in-auth0-... | [email protected] | trust.okta.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Upgrade the Auth0 AD/LDAP Connector to version 7.0.0 or greater.
There are currently no legacy QID mappings associated with this CVE.