Authentik Security authentik是Authentik Security组织的一个用于现代 SSO 的开源身份提供商 (IdP)。 Authentik Security authentik 2026.5.6及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于SCIM组摄取功能未验证源范围与目标组,可能允许具有源范围SCIM配置令牌的攻击者通过配置与现有管理员组同名的SCIM组获取超级用户权限,并锁定所有现有管理员。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Authentik Security | authentik | ≤ 2026.5.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Authentik Security | authentik | 0 ~ 2026.5.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet