authentik 是一个开源的身份提供商。在版本 2026.2.7、2026.5.7 和 2026.8.2 之前,当某个账户对受影响的配置拥有“查看”权限时,即使该账户未被授权修改该配置或读取其密钥,authentik API 序列化器仍会返回已存储的凭据。 受影响的配置类型包括: 通过电子邮件或短信发送的一次性代码投递功能 出站配置目标(outbound provisioning targets) 设备信任集成(device trust integrations) 身份源(identity sources) K
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| goauthentik | authentik | < 2026.2.7 |
affected |
>= 2026.5.0, < 2026.5.7 |
affected | ||
>= 2026.8.0, < 2026.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goauthentik | authentik | < 2026.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94606 | 8.9 HIGH | authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage |
| CVE-2026-94609 | 8.8 HIGH | authentik: Privilege Escalation to Superuser via Group Hierarchy |
| CVE-2026-94613 | 7.5 HIGH | authentik: Denial of Service via Document Type Declarations in SAML Messages |
| CVE-2026-94612 | 7.4 HIGH | authentik: Authentication bypass via assertion confusion in SAML sources |
No comments yet