Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

authentik — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in authentik, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the open-source identity provider authentik. The collection focuses on security flaws disclosed in recent years, covering the time range from 2022 to the present. Readers can use this resource to track vendor security advisories, understand common weakness classes affecting the product, and review its historical vulnerability patterns. The aggregated data helps security teams monitor the current risk landscape without manually parsing individual reports. By consolidating these findings, the page provides a clear overview of how vulnerabilities impact authentik deployments, supporting informed decisions about patching and configuration adjustments.

Vendor: goauthentik

CVE ID Title CVSS Severity Published
CVE-2024-52289 authentik has an insecure default configuration for OAuth2 Redirect URIs CWE-185 6.1AI Medium AI 2024-11-21
CVE-2024-52307 authentik allows a timing attack due to missing constant time comparison for metrics view CWE-208 9.1AI Critical AI 2024-11-21
CVE-2024-47077 authentik cross-provider token validation problems CWE-863 6.5 Medium 2024-09-27
CVE-2024-47070 authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP header CWE-287 9.1 Critical 2024-09-27
CVE-2024-42490 authentik has Insufficient Authorization for several API endpoints CWE-285 7.5 High 2024-08-22
CVE-2024-38371 Insufficient access control for OAuth2 Device Code flow in authentik CWE-284 8.6 High 2024-06-28
CVE-2024-37905 Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik CWE-284 8.8 High 2024-06-28
CVE-2024-23647 PKCE downgrade attack in Authentik CWE-287 6.5 Medium 2024-01-30
CVE-2024-21637 XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Mode CWE-79 7.7 High 2024-01-11
CVE-2023-48228 OAuth2: PKCE can be fully circumvented CWE-287 7.5 High 2023-11-21
CVE-2023-46249 authentik potential installation takeover when default admin user is deleted CWE-287 9.7 Critical 2023-10-31
CVE-2023-39522 Username enumeration attack in goauthentik CWE-203 5.3 Medium 2023-08-29
CVE-2023-36456 Authentik lacks Proxy IP headers validation CWE-436 8.3 High 2023-07-06
CVE-2023-26481 Insufficient user check in FlowTokens by Email stage CWE-345 9.1 Critical 2023-03-04
CVE-2022-46172 authentik allows existing authenticated users to create arbitrary accounts CWE-269 6.4 Medium 2022-12-28
CVE-2022-23555 authentik vulnerable to Improper Authentication via invitation URL token reuse CWE-287 9.4 Critical 2022-12-28
CVE-2022-46145 authentik vulnerable to unauthorized user creation and potential account takeover CWE-287 8.1 High 2022-12-02

All 47 known CVE vulnerabilities affecting authentik with full Chinese analysis, references, and POCs where available.