CVE-2026-85981: Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector
The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Auth0 AD/LDAP Connectorto a version that resolves this vulnerability.Fixed in 7.0.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access to the host running the connector, either as a low-privileged user or through a process executing on that host. Remote-only attackers are not described as able to reach the loopback-only administrative panel directly.
What could an attacker obtain or change?
A local attacker can access management endpoints without credentials, read connector configuration details including plaintext Active Directory service account credentials, and modify connector settings.
Which versions are affected?
The issue affects Auth0 AD/LDAP Connector version 6.5.0 and earlier.