Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94611— authentik: Stored credentials are readable with view permission alone

Quick assessment

Affected
goauthentik authentik
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

authentik 是一个开源的身份提供商。在版本 2026.2.7、2026.5.7 和 2026.8.2 之前,当某个账户对受影响的配置拥有“查看”权限时,即使该账户未被授权修改该配置或读取其密钥,authentik API 序列化器仍会返回已存储的凭据。 受影响的配置类型包括: 通过电子邮件或短信发送的一次性代码投递功能 出站配置目标(outbound provisioning targets) 设备信任集成(device trust integrations) 身份源(identity sources) K

CVSS 8.1 · High EPSS 0.33% · P24

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 3

VendorProduct Version RangeStatus
goauthentik authentik < 2026.2.7 affected
>= 2026.5.0, < 2026.5.7 affected
>= 2026.8.0, < 2026.8.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94611

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
authentik: Stored credentials are readable with view permission alone
Source: CVE Program / CVE List V5
Vulnerability Description
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications using a client or shared secret, and applications using a proxy provider. Deployments are affected when view permission is granted to accounts that are not intended to read these credentials; deployments where every viewer is permitted to read them are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
goauthentik authentik < 2026.2.7 -

II. Public POCs for CVE-2026-94611

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94611

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-94611 (4)

Vendor Advisories for CVE-2026-94611 (2)

Vendor Pages for CVE-2026-94611 (4)

Same Patch Batch · goauthentik · 2026-09-24 · 5 CVEs total

CVE-2026-94606 8.9 HIGH authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage
CVE-2026-94609 8.8 HIGH authentik: Privilege Escalation to Superuser via Group Hierarchy
CVE-2026-94613 7.5 HIGH authentik: Denial of Service via Document Type Declarations in SAML Messages
CVE-2026-94612 7.4 HIGH authentik: Authentication bypass via assertion confusion in SAML sources

IV. Related Vulnerabilities

V. Comments for CVE-2026-94611

No comments yet


Leave a comment