Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94606— authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage

Quick assessment

Affected
goauthentik authentik
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

authentik 是一款开源的身份提供商(Identity Provider)。在版本 2026.2.7、2026.5.7 和 2026.8.2 之前,authentik 的邮件身份验证器在身份验证或注册流程中,会接受用户在设置请求中提供的收件人地址,而不是使用流程中已预先确定的地址。攻击者若已知目标用户的密码,即可将目标用户的电子邮件地址替换为自己控制的地址,从而接收一次性验证码,并完成该身份验证因子的注册。此漏洞仅在目标用户尚未注册邮件身份验证因子的情况下成立。成功注册后,攻击者即可获得目标用户的会话权限,进

CVSS 8.9 · High EPSS 0.49% · P40

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 3

VendorProduct Version RangeStatus
goauthentik authentik < 2026.2.7 affected
>= 2026.5.0, < 2026.5.7 affected
>= 2026.8.0, < 2026.8.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94606

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage
Source: CVE Program / CVE List V5
Vulnerability Description
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a target user's password can substitute an attacker-controlled address, receive the one-time code, and finish enrolling the factor as the target. The target must not have enrolled the email factor already. Successful enrollment gives the actor a session as the target and access to single sign-on applications behind the account. Other authenticator types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
goauthentik authentik < 2026.2.7 -

II. Public POCs for CVE-2026-94606

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94606

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-94606 (8)

Vendor Advisories for CVE-2026-94606 (2)

Vendor Pages for CVE-2026-94606 (4)

Same Patch Batch · goauthentik · 2026-09-24 · 5 CVEs total

CVE-2026-94609 8.8 HIGH authentik: Privilege Escalation to Superuser via Group Hierarchy
CVE-2026-94611 8.1 HIGH authentik: Stored credentials are readable with view permission alone
CVE-2026-94613 7.5 HIGH authentik: Denial of Service via Document Type Declarations in SAML Messages
CVE-2026-94612 7.4 HIGH authentik: Authentication bypass via assertion confusion in SAML sources

IV. Related Vulnerabilities

V. Comments for CVE-2026-94606

No comments yet


Leave a comment