Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94612— authentik: Authentication bypass via assertion confusion in SAML sources

Quick assessment

Affected
goauthentik authentik
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

authentik 是一款开源的身份提供商(Identity Provider)。在版本 2026.2.7、2026.5.7 和 2026.8.2 之前,authentik 的 SAML Source 会验证断言(assertion)的签名及其有效期,但并未确保该断言是由为该 Source 配置的身份提供商签发的,也未验证其是否是对该 Source 发出的登录请求的响应。此外,SAML Source 不会记录已接受过的断言,从而导致断言可被重放(replay)。攻击者若持有此类有效的断言,便可以使用本应发往其他服务

CVSS 7.4 · High EPSS 0.27% · P17

Possible ATT&CK Techniques 1 AI

T1110.003 · Password Spraying

Affected Version Matrix 3

VendorProduct Version RangeStatus
goauthentik authentik < 2026.2.7 affected
>= 2026.5.0, < 2026.5.7 affected
>= 2026.8.0, < 2026.8.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94612

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
authentik: Authentication bypass via assertion confusion in SAML sources
Source: CVE Program / CVE List V5
Vulnerability Description
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML Source also does not record already accepted assertions, allowing replay. An unauthenticated actor who possesses such a valid assertion can use an assertion intended for another service provider or reuse an earlier assertion to authenticate as the user named by the assertion. Only SAML Sources are affected; SAML Providers and other Source types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
goauthentik authentik < 2026.2.7 -

II. Public POCs for CVE-2026-94612

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94612

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-94612 (4)

Vendor Advisories for CVE-2026-94612 (2)

Vendor Pages for CVE-2026-94612 (4)

Same Patch Batch · goauthentik · 2026-09-24 · 5 CVEs total

CVE-2026-94606 8.9 HIGH authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage
CVE-2026-94609 8.8 HIGH authentik: Privilege Escalation to Superuser via Group Hierarchy
CVE-2026-94611 8.1 HIGH authentik: Stored credentials are readable with view permission alone
CVE-2026-94613 7.5 HIGH authentik: Denial of Service via Document Type Declarations in SAML Messages

IV. Related Vulnerabilities

V. Comments for CVE-2026-94612

No comments yet


Leave a comment