Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

authentik — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in authentik, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the open-source identity provider authentik. The collection focuses on security flaws disclosed in recent years, covering the time range from 2022 to the present. Readers can use this resource to track vendor security advisories, understand common weakness classes affecting the product, and review its historical vulnerability patterns. The aggregated data helps security teams monitor the current risk landscape without manually parsing individual reports. By consolidating these findings, the page provides a clear overview of how vulnerabilities impact authentik deployments, supporting informed decisions about patching and configuration adjustments.

Vendor: goauthentik

CVE ID Title CVSS Severity Published
CVE-2026-94606 authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage CWE-287 8.9 High 2026-09-24
CVE-2026-94609 authentik: Privilege Escalation to Superuser via Group Hierarchy CWE-269 8.8 High 2026-09-24
CVE-2026-94611 authentik: Stored credentials are readable with view permission alone CWE-200 8.1 High 2026-09-24
CVE-2026-94612 authentik: Authentication bypass via assertion confusion in SAML sources CWE-287 7.4 High 2026-09-24
CVE-2026-94613 authentik: Denial of Service via Document Type Declarations in SAML Messages CWE-770 7.5 High 2026-09-24
CVE-2026-57580 authentik: Account Takeover via SAML NameID Comment Truncation CWE-436 9.4 Critical 2026-08-18
CVE-2026-55106 authentik: Unauthenticated LDAP directory data disclosure CWE-862 5.3 Medium 2026-08-18
CVE-2026-61574 authentik RAC: access any endpoint via an unrelated application CWE-639 8.8 High 2026-08-18
CVE-2026-54730 authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView CWE-284 8.6 High 2026-08-18
CVE-2026-72537 Authentik Security authentik - Privilege Escalation CWE-269 8.8 High 2026-08-11
CVE-2026-72534 Authentik Security authentik - Privilege Escalation CWE-269 8.8 High 2026-08-11
CVE-2026-49448 authentik: SourceStage bypass via empty POST CWE-287 9.8 Critical 2026-06-02
CVE-2026-49443 authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API CWE-287 8.8 High 2026-06-02
CVE-2026-47201 authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user CWE-20 8.5 High 2026-06-02
CVE-2026-42849 authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover CWE-79 9.3 Critical 2026-06-02
CVE-2026-41569 authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints CWE-601 - - 2026-06-02
CVE-2026-41577 authentik: SAML source does not validate Conditions, timing, or audience on assertions CWE-345 - - 2026-06-02
CVE-2026-40172 authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser CWE-269 8.1 High 2026-05-22
CVE-2026-40166 authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/ CWE-200 - - 2026-05-22
CVE-2026-40165 authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation CWE-287 8.7 High 2026-05-20
CVE-2026-25922 authentik has a Signature Verification Bypass via SAML Assertion Wrapping CWE-287 8.8 High 2026-02-12
CVE-2026-25748 authentik has a forward authentication bypass with broken cookie CWE-287 8.6 High 2026-02-12
CVE-2026-25227 authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint CWE-94 9.1 Critical 2026-02-12
CVE-2025-64708 authentik invitation expiry is delayed by at least 5 minutes CWE-613 5.8 Medium 2025-11-19
CVE-2025-64521 authentik deactivated service accounts can authenticate to OAuth CWE-289 4.8 Medium 2025-11-19
CVE-2025-53942 authentik has an insufficient check for account active status during OAuth/SAML authentication CWE-269 7.0 - 2025-07-23
CVE-2025-52553 authentik has Insufficient Session verification for Remote Access Control endpoint access CWE-287 9.1AI Critical AI 2025-06-27
CVE-2025-29928 authentik's deletion of sessions did not revoke sessions when using database session storage CWE-384 8.0 High 2025-03-28
CVE-2024-11623 Stored XSS in authentik CWE-79 4.8 - 2025-02-04
CVE-2024-52287 authentik performs insufficient validation of OAuth scopes CWE-285 7.5AI High AI 2024-11-21

All 47 known CVE vulnerabilities affecting authentik with full Chinese analysis, references, and POCs where available.