cbcvebase.

Goauthentik Authentik vulnerabilities

45 known vulnerabilities affecting goauthentik/authentik.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH24MEDIUM11

Vulnerabilities

Page 2 of 3
CVE-2022-23555P3HIGHCVSS 8.8fixed in 2022.10.4≥ 2022.11.0, < 2022.11.4+2 more2022-12-28
CVE-2022-23555 [HIGH] CWE-287 CVE-2022-23555: authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow than in the one provided. The vulnerability allows an attacker that knows dif
nvd
CVE-2024-52289P3CRITICALCVSS 9.8fixed in 2024.8.5≥ 2024.10.0, < 2024.10.3+1 more2024-11-21
CVE-2024-52289 [CRITICAL] CWE-185 CVE-2024-52289: authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value received as an allowed redirect URI, without escaping characters that have a special meaning in RegEx. Si
nvd
CVE-2026-25227P3HIGHCVSS 7.2≥ 2021.3.1, < 2025.8.6≥ 2025.10.0, < 2025.10.4+4 more2026-02-12
CVE-2026-25227 [HIGH] CWE-94 CVE-2026-25227: authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025 authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the authentik server container through the test endpoint, which is intended to prev
nvd
CVE-2026-42849P3CRITICALCVSS 9.3fixed in 2025.12.5≥ 2026.2.0, < 2026.2.3+1 more2026-06-02
CVE-2026-42849 [CRITICAL] CWE-79 CVE-2026-42849: authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.
nvd
CVE-2024-23647P3HIGHCVSS 8.8fixed in 2023.8.7≥ 2023.10.0, < 2023.10.7+1 more2024-01-30
CVE-2024-23647 [HIGH] CWE-287 CVE-2024-23647: Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that all Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_verifier parameter to the token request. Prior to 2023.8.7 and 2023.10.7, a downgrade scenario is possib
nvd
CVE-2025-53942P3HIGHCVSS 7.4fixed in 2025.4.4≥ 2025.6.0, < 2025.6.4+2 more2025-07-23
CVE-2025-53942 [HIGH] CWE-269 CVE-2025-53942: authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with supp authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered through OAuth/SAML or linked their accounts to OAuth/SAML providers can still retain partial access to
nvd
CVE-2026-94612P3HIGHCVSS 7.4fixed in 2026.2.7v>= 2026.5.0, < 2026.5.7+1 more2026-09-24
CVE-2026-94612 [HIGH] CWE-287 CVE-2026-94612: authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authent authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML Source also does not record already acc
nvd
CVE-2026-94613P3HIGHCVSS 7.5fixed in 2026.2.7v>= 2026.5.0, < 2026.5.7+1 more2026-09-24
CVE-2026-94613 [HIGH] CWE-770 CVE-2026-94613: authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthe authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or /source/saml/*, causing the requests assigne
nvd
CVE-2024-42490P3HIGHCVSS 7.5fixed in 2024.4.4≥ 2024.6.0, < 2024.6.4+1 more2024-08-22
CVE-2024-42490 [HIGH] CWE-285 CVE-2024-42490: authentik is an open-source Identity Provider. Several API endpoints can be accessed by users withou authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs//view_certificate/, /api/v3/crypto/certificatekeypairs//view_private_key/, and /api/v3/.../used_by/. Note that all of the affected API
nvd
CVE-2026-41577P3HIGHCVSS 7.5fixed in 2025.12.5≥ 2026.2.0, < 2026.2.3+1 more2026-06-02
CVE-2026-41577 [HIGH] CWE-345 CVE-2026-41577: authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML so authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored. This allows replay of expired assertions and acceptance of assertions intended
nvd
CVE-2025-29928P3HIGHCVSS 8.0fixed in 2024.12.4≥ 2025.2.0, < 2025.2.3+1 more2025-03-28
CVE-2025-29928 [HIGH] CWE-384 CVE-2025-29928: authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authen authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would not revoke the session and the session holder would continue to have access to authentik. authentik 202
nvd
CVE-2026-40166P3HIGHCVSS 7.1fixed in 2025.12.5v>= 2026.2.0-rc1, < 2026.2.32026-05-22
CVE-2026-40166 [HIGH] CWE-200 CVE-2026-40166: authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 throu authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they have previously authenticated against, exposing sensitive information to users without the correct perm
cvelistv5nvd
CVE-2023-36456P3HIGHCVSS 7.3fixed in 2023.4.3≥ 2023.5.0, < 2023.5.5+1 more2023-07-06
CVE-2023-36456 [HIGH] CWE-436 CVE-2023-36456: authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik do authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and the go code. Only authentik setups that are directly accessible by users without a reverse proxy are susceptible to this. Possible spoofing of IP addresse
nvd
CVE-2024-52287P3HIGHCVSS 7.2fixed in 2024.8.5≥ 2024.10.0, < 2024.10.3+1 more2024-11-21
CVE-2024-52287 [HIGH] CWE-285 CVE-2024-52287: authentik is an open-source identity provider. When using the client_credentials or device_code OAut authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.
nvd
CVE-2022-46172P3MEDIUMCVSS 6.4≥ 2022.10.0, < 2022.10.4≥ 2022.11.0, < 2022.11.4+2 more2022-12-28
CVE-2022-46172 [MEDIUM] CWE-269 CVE-2022-46172: authentik is an open-source Identity provider focused on flexibility and versatility. In versions pr authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where it is undesirable for users to create new accounts by themselves. This
nvd
CVE-2024-47077P3MEDIUMCVSS 6.5fixed in 2024.6.5≥ 2024.8.0, < 2024.8.3+1 more2024-09-27
CVE-2024-47077 [MEDIUM] CWE-863 CVE-2024-47077: authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access token authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were legitimately issued for one application and use it to access another appl
nvd
CVE-2023-26481P3MEDIUMCVSS 6.5fixed in 2022.12.3≤ 2023.1.3+4 more2023-03-04
CVE-2023-26481 [MEDIUM] CWE-345 CVE-2023-26481: authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user. This attack is only possible if a recovery flow exists, which has both an Identification and an Email stage bound to it. If the flo
nvd
CVE-2026-55106P4MEDIUMCVSS 5.3fixed in 2026.2.6v>= 2026.5.0, < 2026.5.52026-08-18
CVE-2026-55106 [MEDIUM] CWE-862 CVE-2026-55106: authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action o authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, including an unauthenticated client, can invoke the diagnostic action against a configured LDAP Source. The
nvd
CVE-2026-41569P4MEDIUMCVSS 6.1fixed in 2026.2.32026-06-02
CVE-2026-41569 [MEDIUM] CWE-601 CVE-2026-41569: authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link can supply a wreply value on a different origin that passes the check (e.g. https://portal.example.com
nvd
CVE-2024-52307P4MEDIUMCVSS 5.6fixed in 2024.8.5≥ 2024.10.0, < 2024.10.3+1 more2024-11-21
CVE-2024-52307 [MEDIUM] CWE-208 CVE-2024-52307: authentik is an open-source identity provider. Due to the usage of a non-constant time comparison fo authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the SECRET_KEY, which is used to authenticate the endpoint. The /-/metrics/ endpoint returns Prometheus metrics and is not intended to be accessed directly, as the Go proxy running in the authe
nvd
Goauthentik Authentik vulnerabilities | cvebase