cbcvebase.

Goauthentik Authentik vulnerabilities

45 known vulnerabilities affecting goauthentik/authentik.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH24MEDIUM11

Vulnerabilities

Page 1 of 3
CVE-2026-40165P2HIGHCVSS 8.7fixed in 2025.12.5v>= 2026.2.0-rc1, < 2026.2.32026-05-21
CVE-2026-40165 [HIGH] CWE-91 CVE-2026-40165: authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-r authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick authentik into only seeing a part of t
nvd
CVE-2026-61574P2HIGHCVSS 8.8fixed in 2026.2.6v>= 2026.5.0, < 2026.5.52026-08-18
CVE-2026-61574 [HIGH] CWE-639 CVE-2026-61574: authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Con authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The endpoint listing does not apply t
nvd
CVE-2026-94606P2HIGHCVSS 8.9fixed in 2026.2.7v>= 2026.5.0, < 2026.5.7+1 more2026-09-24
CVE-2026-94606 [HIGH] CWE-287 CVE-2026-94606: authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a target user's password can substitute
nvd
CVE-2026-57580P2CRITICALCVSS 9.4fixed in 2026.2.6v>= 2026.5.0, < 2026.5.52026-08-18
CVE-2026-57580 [CRITICAL] CWE-436 CVE-2026-57580: authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Sourc authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An attacker with an account on the source identity provider who can set
nvd
CVE-2026-94609P3HIGHCVSS 8.8fixed in 2026.2.7v>= 2026.5.0, < 2026.5.7+1 more2026-09-24
CVE-2026-94609 [HIGH] CWE-269 CVE-2026-94609: authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistent
nvd
CVE-2026-49443P3HIGHCVSS 8.8fixed in 2025.12.6≥ 2026.2.0, < 2026.2.4+3 more2026-06-02
CVE-2026-49443 [HIGH] CWE-287 CVE-2026-49443: authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.
nvd
CVE-2026-54730P3HIGHCVSS 8.6fixed in 2026.2.6v>= 2026.5.0, < 2026.5.52026-08-18
CVE-2026-54730 [HIGH] CWE-284 CVE-2026-54730: authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome D
nvd
CVE-2023-46249P2CRITICALCVSS 9.8fixed in 2023.8.4≥ 2023.10.0, < 2023.10.2+1 more2023-10-31
CVE-2023-46249 [CRITICAL] CWE-287 CVE-2023-46249: authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the de authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint to create the default admin user, which can also optionally set the de
nvd
CVE-2022-46145P3CRITICALCVSS 9.8fixed in 2022.10.2≥ 2022.11, < 2022.11.2+1 more2022-12-02
CVE-2022-46145 [CRITICAL] CWE-287 CVE-2022-46145: authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnera authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows for email-verified password recovery, this can be used to overwrite th
nvd
CVE-2024-37905P3HIGHCVSS 8.8fixed in 2024.2.4≥ 2024.4.0, < 2024.4.3+2 more2024-06-28
CVE-2024-37905 [HIGH] CWE-284 CVE-2024-37905: authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been
nvd
CVE-2026-49448P3CRITICALCVSS 9.8fixed in 2025.12.6≥ 2026.2.0, < 2026.2.4+3 more2026-06-02
CVE-2026-49448 [CRITICAL] CWE-287 CVE-2026-49448: authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.
nvd
CVE-2024-47070P3CRITICALCVSS 9.0fixed in 2024.6.5≥ 2024.8.0, < 2024.8.3+1 more2024-09-27
CVE-2024-47070 [CRITICAL] CWE-287 CVE-2024-47070: authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024 authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any account with a known login or email address. The vulnerability requires the
nvd
CVE-2026-40172P3HIGHCVSS 8.1fixed in 2025.12.5v>= 2026.2.0-rc1, < 2026.2.32026-05-22
CVE-2026-40172 [HIGH] CWE-269 CVE-2026-40172: authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 throu authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring enable_group_superuser, leading to privil
cvelistv5nvd
CVE-2026-25922P3HIGHCVSS 8.8fixed in 2025.8.6≥ 2025.10.0, < 2025.10.4+3 more2026-02-12
CVE-2026-25922 [HIGH] CWE-287 CVE-2026-25922: authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when usi authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificate setting under Advanced Protocol settings configured, it was possible fo
nvd
CVE-2026-47201P3HIGHCVSS 8.5fixed in 2025.12.6≥ 2026.2.0, < 2026.2.4+4 more2026-06-02
CVE-2026-47201 [HIGH] CWE-20 CVE-2026-47201: authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue
nvd
CVE-2023-48228P3CRITICALCVSS 9.8fixed in 2023.8.5≥ 2023.10.0, < 2023.10.4+1 more2023-11-21
CVE-2023-48228 [CRITICAL] CWE-287 CVE-2023-48228: authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challeng authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during the token step. Prior to versions 2023.10.4 and 2023.8.5, authentik checks if the contents of
nvd
CVE-2026-25748P3HIGHCVSS 7.5fixed in 2025.10.4≥ 2025.12.0, < 2025.12.4+2 more2026-02-12
CVE-2026-25748 [HIGH] CWE-287 CVE-2026-25748: authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed co authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. When a malicious cookie was used, none of the authentik-specific X-Authentik
nvd
CVE-2024-38371P3CRITICALCVSS 9.8fixed in 2024.2.4≥ 2024.4.0, < 2024.4.3+2 more2024-06-28
CVE-2024-38371 [CRITICAL] CWE-284 CVE-2024-38371: authentik is an open-source Identity Provider. Access restrictions assigned to an application were n authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This issue has been patched in version(s) 2024.6.0, 2024.2.4 and 2024.4.3.
nvd
CVE-2026-94611P3HIGHCVSS 8.1fixed in 2026.2.7v>= 2026.5.0, < 2026.5.7+1 more2026-09-24
CVE-2026-94611 [HIGH] CWE-200 CVE-2026-94611: authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery b
nvd
CVE-2025-52553P3CRITICALCVSS 9.6fixed in 2025.4.3≥ 2025.6.0, < 2025.6.3+1 more2025-06-27
CVE-2025-52553 [CRITICAL] CWE-287 CVE-2025-52553: authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session of the user who authorized the connection, however this check is missing in versions prior to 2025.6
nvd
Goauthentik Authentik vulnerabilities | cvebase