Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85982— Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector

Quick assessment

Affected
Auth0 Auth0 AD/LDAP Connector
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Auth0 的 AD/LDAP 连接器存在存储型跨站脚本(Stored XSS)漏洞,原因在于管理面板中展示搜索结果的更新日志内容时,HTML 编码处理不当。拥有修改目录属性权限的已认证用户,或连接器所在主机上具有低权限的本地用户,可以插入脚本内容。当管理员查看受影响的搜索结果或更新日志时,这些脚本内容将在其浏览器中执行。

CVSS 9.0 · Critical

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85982

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector
Source: CVE Program / CVE List V5
Vulnerability Description
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search results or update logs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Auth0 Auth0 AD/LDAP Connector 0 ~ 6.5.0 -

II. Public POCs for CVE-2026-85982

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85982

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85982 (1)

Same Patch Batch · Auth0 · 2026-09-08 · 4 CVEs total

CVE-2026-85983 7.8 HIGH Local Privilege Escalation in Auth0 AD/LDAP Connector
CVE-2026-85981 6.7 MEDIUM Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector
CVE-2026-84685 6.5 MEDIUM Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Managemen

IV. Related Vulnerabilities

V. Comments for CVE-2026-85982

No comments yet


Leave a comment