Vulnerabilities & PatchesEmerging1 src
Critical Auth0 AD/LDAP Connector Flaw Lets Attackers Execute Stored XSS in Admin Browsers
Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway, including a critical stored cross-site scripting flaw that could execute attacker-controlled code in an administrator’s browser.
The vulnerabilities, disclosed on September 8, 2026, include stored XSS, authorization bypass, and SQL injection issues.
Organizations using the affected identity infrastructure should prioritize remediation, especially where Access Gateway secures sensitive enterprise applications or privileged IT personnel administer Auth0 directory connectors.
Critical Auth0 AD/LDAP Connector Flaw
The most severe vulnerability, CVE-2026-85982 , impacts the Auth0 AD/LDAP Connector and carries a CVSS v3 score of 9. 0.