Skip to content
OktaCVE-2026-85981

Okta Auth0 AD/LDAP Connector: missing authentication

Medium6.7CVE-2026-85981 · Published Sep 8, 2026 · updated Sep 10, 2026

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints, a local user can read configuration details, including plaintext Active Directory service account credentials, and modify connector settings.

Okta advisory

Affected versions

PackageAffectedFixed in
Auth0 AD/LDAP Connector
Product
<= 6.5.0No fix yet
Details and references

More Okta advisories

All Okta
Advisory
Okta Auth0 AD/LDAP Connector: cross-site scripting
Critical9.0Sep 8
Okta Auth0 AD/LDAP Connector: code execution
High7.8Sep 8
The react-native-auth0 SDK's web platform implementation does not scope its...
Medium6.5Sep 8
Okta Verify for Windows: link following
Medium6.0Sep 8
The Okta Hyperdrive agent plugin returns a success response without a signed...
Medium5.6Sep 8
Okta Access Gateway: command injection
Medium6.7Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.