authentik 是一款开源的身份提供商(Identity Provider)。在版本 2026.2.7、2026.5.7 和 2026.8.2 之前,authentik 的 SAML Source 会验证断言(assertion)的签名及其有效期,但并未确保该断言是由为该 Source 配置的身份提供商签发的,也未验证其是否是对该 Source 发出的登录请求的响应。此外,SAML Source 不会记录已接受过的断言,从而导致断言可被重放(replay)。攻击者若持有此类有效的断言,便可以使用本应发往其他服务
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| goauthentik | authentik | < 2026.2.7 |
affected |
>= 2026.5.0, < 2026.5.7 |
affected | ||
>= 2026.8.0, < 2026.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goauthentik | authentik | < 2026.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94606 | 8.9 HIGH | authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage |
| CVE-2026-94609 | 8.8 HIGH | authentik: Privilege Escalation to Superuser via Group Hierarchy |
| CVE-2026-94611 | 8.1 HIGH | authentik: Stored credentials are readable with view permission alone |
| CVE-2026-94613 | 7.5 HIGH | authentik: Denial of Service via Document Type Declarations in SAML Messages |
No comments yet