OktaCVE-2026-85983
Okta Auth0 AD/LDAP Connector: code execution
High7.8CVE-2026-85983 · Published Sep 8, 2026 · updated Sep 10, 2026
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Auth0 AD/LDAP Connector Product | <= 6.5.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-94
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Okta Auth0 AD/LDAP Connector: missing authentication | Medium6.7 | No fix yet |
| Sep 8 | Okta Auth0 AD/LDAP Connector: cross-site scripting | Critical9.0 | No fix yet |
| Sep 8 | The react-native-auth0 SDK's web platform implementation does not scope its... | Medium6.5 | 5.11.1 |
| Sep 8 | Okta Verify for Windows: link following | Medium6.0 | 7.0.0 |
| Sep 8 | The Okta Hyperdrive agent plugin returns a success response without a signed... | Medium5.6 | 1.5.2 |
| Sep 8 | Okta Access Gateway: command injection | Medium6.7 | 2026.9.1 |