Auth0 AD/LDAP 连接器(6.5.0 及更早版本)的管理面板在本地回环接口上监听,且无需身份验证。这使得宿主机上的本地低权限用户或进程能够在无凭证的情况下访问该面板的管理端点。通过这些端点,本地用户可以读取配置详情(包括明文存储的 Active Directory 服务账户凭据),并且可以修改连接器的设置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Auth0 | Auth0 AD/LDAP Connector | 0 ~ 6.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85982 | 9.0 CRITICAL | Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector |
| CVE-2026-85983 | 7.8 HIGH | Local Privilege Escalation in Auth0 AD/LDAP Connector |
| CVE-2026-84685 | 6.5 MEDIUM | Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Managemen |
No comments yet