Authentik Security authentik是Authentik Security组织的一个用于现代 SSO 的开源身份提供商 (IdP)。 Authentik Security authentik 2026.2.6之前版本和2026.5.0至2026.5.5之前版本存在授权问题漏洞,该漏洞源于LDAP Source API的诊断操作未强制执行对象级读取授权过滤器,可能导致未经身份验证的客户端调用诊断操作,泄露目录结构、命名约定及特定账户和组的存在信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| goauthentik | authentik | < 2026.2.6 |
affected |
>= 2026.5.0, < 2026.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goauthentik | authentik | < 2026.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57580 | 9.4 CRITICAL | authentik: Account Takeover via SAML NameID Comment Truncation |
| CVE-2026-61574 | 8.8 HIGH | authentik RAC: access any endpoint via an unrelated application |
| CVE-2026-54730 | 8.6 HIGH | authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndp |
No comments yet