Auth0 AD/LDAP 连接器在服务启动过程中对配置值的处理不当。这使得主机系统上的低权限用户能够修改该连接器的配置。当服务重启时,被修改的配置可能导致以该服务账户的权限执行代码(即代码执行漏洞)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Auth0 | Auth0 AD/LDAP Connector | 0 ~ 6.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85982 | 9.0 CRITICAL | Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector |
| CVE-2026-85981 | 6.7 MEDIUM | Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector |
| CVE-2026-84685 | 6.5 MEDIUM | Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Managemen |
No comments yet