The full story
Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector CVE-2026-85982 - Sep 8, 2026. CVE-2026-85982 is the vulnerability identifier associated with this report. The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel.
To remediate, upgrade the auth0/ad-ldap-connector to version 7 0 0 or greater.
What the reporting is based on
Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector CVE-2026-85982 - Sep 8, 2026
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. To remediate, upgrade the auth0/ad-ldap-connector to version 7 0 0 or greater.
Open sourceReporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What this means
Risk depends on whether the affected technology and the affected component are deployed and reachable. Exposure, privilege, business criticality and compensating controls should determine remediation priority.
What security teams should check now
- Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-85982 and validate the affected path after remediation.
What is not yet confirmed
- Available reporting does not currently indicate exploitation, but that can change as vendor, government or threat-intelligence reporting develops.