authentik 是一款开源的身份提供商(Identity Provider)。在版本 2026.2.7、2026.5.7 和 2026.8.2 之前,authentik 的邮件身份验证器在身份验证或注册流程中,会接受用户在设置请求中提供的收件人地址,而不是使用流程中已预先确定的地址。攻击者若已知目标用户的密码,即可将目标用户的电子邮件地址替换为自己控制的地址,从而接收一次性验证码,并完成该身份验证因子的注册。此漏洞仅在目标用户尚未注册邮件身份验证因子的情况下成立。成功注册后,攻击者即可获得目标用户的会话权限,进
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| goauthentik | authentik | < 2026.2.7 |
affected |
>= 2026.5.0, < 2026.5.7 |
affected | ||
>= 2026.8.0, < 2026.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goauthentik | authentik | < 2026.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94609 | 8.8 HIGH | authentik: Privilege Escalation to Superuser via Group Hierarchy |
| CVE-2026-94611 | 8.1 HIGH | authentik: Stored credentials are readable with view permission alone |
| CVE-2026-94613 | 7.5 HIGH | authentik: Denial of Service via Document Type Declarations in SAML Messages |
| CVE-2026-94612 | 7.4 HIGH | authentik: Authentication bypass via assertion confusion in SAML sources |
No comments yet