SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-85982

CRITICAL · CVSS 9 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) due to inadequate HTML encoding in the admin panel's search results and updater logs. This flaw allows authenticated users with the ability to modify directory attributes, or low-privileged local users, to inject malicious scripts that execute in the browser of administrators viewing the affected content. Organizations using this connector should prioritize remediation to protect against potential exploitation that could compromise sensitive administrative sessions.

CVE
CVE-2026-85982
Severity
CRITICAL
CVSS
9
EPSS
0.22%

Original NVD Description

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search results or update logs.