Auth0 的 AD/LDAP 连接器存在存储型跨站脚本(Stored XSS)漏洞,原因在于管理面板中展示搜索结果的更新日志内容时,HTML 编码处理不当。拥有修改目录属性权限的已认证用户,或连接器所在主机上具有低权限的本地用户,可以插入脚本内容。当管理员查看受影响的搜索结果或更新日志时,这些脚本内容将在其浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Auth0 | Auth0 AD/LDAP Connector | 0 ~ 6.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85983 | 7.8 HIGH | Local Privilege Escalation in Auth0 AD/LDAP Connector |
| CVE-2026-85981 | 6.7 MEDIUM | Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector |
| CVE-2026-84685 | 6.5 MEDIUM | Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Managemen |
No comments yet