ZeroHour

CVE-2026-85983

moderate

Code Injection in Auth0 AD/LDAP Connector Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p3
Published
()
Modified
AI analysis

The Auth0 AD/LDAP Connector (maintained by Okta's PSIRT as the assigning CNA) improperly processes a configuration value during service startup, a flaw classified as improper control of code generation (CWE-94). A low-privileged user with access to the host system can modify the connector's configuration, and when the connector service next restarts, the tampered configuration is processed in a way that executes attacker-controlled code. An attacker gains code execution with the privileges of the connector's service account, which typically runs with elevated rights on the host, making this an effective local privilege escalation that can lead to full compromise of the connector server and, from there, the directory-integration trust with Auth0. Affected organizations are those operating the AD/LDAP Connector on internal servers to bridge on-premises Active Directory or LDAP directories to Auth0. Exploitation has not been observed: there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.1% probability of exploitation within 30 days (3rd percentile).

What to do: Monitor the Okta/Auth0 PSIRT advisory for CVE-2026-85983 and upgrade the AD/LDAP Connector to the patched release as soon as a fixed version is published, since no fixed version is stated in the current data. As an interim mitigation, restrict write access to the connector's configuration files and installation directory to administrators only, limit interactive logon rights on the connector host to trusted accounts, and treat unexpected service restarts on connector hosts as suspicious. Because this is a local attack requiring host access, connector servers that are internal-only and tightly controlled carry materially lower risk.

Affected
Okta (Auth0) Auth0 AD/LDAP Connector
Estimated exposure
moderate≈ a few thousand connector deployments worldwide (low thousands of host installations, typically 1–2 connector servers per deploying organization) — The connector is deployed only by the subset of Auth0/Okta customers integrating on-premises AD/LDAP directories, each running one or a few internal connector hosts; there is no public install-count or internet-exposure scan data, so this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.

Weakness
CWE-94
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.