CVE-2026-85983
moderateCode Injection in Auth0 AD/LDAP Connector Enables Local Privilege Escalation
The Auth0 AD/LDAP Connector (maintained by Okta's PSIRT as the assigning CNA) improperly processes a configuration value during service startup, a flaw classified as improper control of code generation (CWE-94). A low-privileged user with access to the host system can modify the connector's configuration, and when the connector service next restarts, the tampered configuration is processed in a way that executes attacker-controlled code. An attacker gains code execution with the privileges of the connector's service account, which typically runs with elevated rights on the host, making this an effective local privilege escalation that can lead to full compromise of the connector server and, from there, the directory-integration trust with Auth0. Affected organizations are those operating the AD/LDAP Connector on internal servers to bridge on-premises Active Directory or LDAP directories to Auth0. Exploitation has not been observed: there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.1% probability of exploitation within 30 days (3rd percentile).
What to do: Monitor the Okta/Auth0 PSIRT advisory for CVE-2026-85983 and upgrade the AD/LDAP Connector to the patched release as soon as a fixed version is published, since no fixed version is stated in the current data. As an interim mitigation, restrict write access to the connector's configuration files and installation directory to administrators only, limit interactive logon rights on the connector host to trusted accounts, and treat unexpected service restarts on connector hosts as suspicious. Because this is a local attack requiring host access, connector servers that are internal-only and tightly controlled carry materially lower risk.
| Okta (Auth0) Auth0 AD/LDAP Connector | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.