authentik是authentik开源的一个身份提供应用程序。 authentik 2026.2.3之前版本存在输入验证错误漏洞,该漏洞源于WS-Federation提供程序使用原始字符串前缀检查而非正确URL解析验证用户提供的wreply参数,可能导致攻击者构造登录链接将受害者浏览器重定向到攻击者控制的基础设施。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| goauthentik | authentik | < 2026.2.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goauthentik | authentik | < 2026.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49448 | 9.8 CRITICAL | authentik: SourceStage bypass via empty POST |
| CVE-2026-42849 | 9.3 CRITICAL | authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover |
| CVE-2026-49443 | 8.8 HIGH | authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable th |
| CVE-2026-47201 | 8.5 HIGH | authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary fe |
| CVE-2026-41577 | authentik: SAML source does not validate Conditions, timing, or audience on assertions |
No comments yet