The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-08 21:18
Updated : 2026-09-10 15:17
NVD link : CVE-2026-85983
Mitre link : CVE-2026-85983
CVE.ORG link : CVE-2026-85983
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
