CVE-2026-85983: Local Privilege Escalation in Auth0 AD/LDAP Connector
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
auth0/ad-ldap-connectorto a version that resolves this vulnerability.Fixed in 7.00 or greater
Event History
Frequently Asked Questions
Who can exploit this issue?
A low-privileged user who already has access to the host system can exploit it by modifying the connector configuration. The issue is local; the provided information does not indicate remote exploitation.
What must happen for the modified configuration to result in code execution?
The Auth0 AD/LDAP Connector service must restart after the configuration is modified. Code execution then occurs with the privileges of the service account.
What is the likely impact if exploitation succeeds?
An attacker can execute code as the connector service account. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.