Authentik Security authentik是Authentik Security组织的一个用于现代 SSO 的开源身份提供商 (IdP)。 Authentik Security authentik 2026.5.6及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于SCIM用户摄取功能未验证范围边界,攻击者可利用有限的SCIM配置令牌接管任何用户账户(包括超级用户),导致权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Authentik Security | authentik | ≤ 2026.5.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Authentik Security | authentik | 0 ~ 2026.5.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet