---
id: CVE-2026-85982
title: >-
  The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS)
  issues due to improper HTML encoding of data in search results and updater log
  content displayed in the admin panel
summary: >-
  The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS)
  issues due to improper HTML encoding of data in search results and updater log
  content displayed in the admin panel. An authenticated user with privileges to
  …
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-79
vendor: Auth0
product: Auth0 AD/LDAP Connector
affected:
  - ad_ldap_connector <= 6.5.0
published: '2026-09-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:17:49.920'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85982'
references:
  - url: >-
      https://trust.okta.com/security-advisories/stored-cross-site-scripting-xss-in-auth0-ad-ldap-connector-cve-2026-85982
    label: psirt@okta.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T14:43:01.622324Z'
epss: 0.00401
epssPercentile: 0.31612
ingestedAt: '2026-09-08T21:11:12.373Z'
---

## Overview

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search results or update logs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
