Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

goauthentik — Vulnerabilities & Security Advisories 45

Browse all 45 CVE security advisories affecting goauthentik. AI-powered Chinese analysis, POCs, and references for each vulnerability.

goauthentik functions as an open-source identity provider, primarily serving as a self-hosted solution for single sign-on and identity governance. Its architecture supports complex authentication workflows, making it a critical component in enterprise access management strategies. Security audits have identified twenty-seven recorded Common Vulnerabilities and Exposures, reflecting the inherent risks of maintaining a complex, feature-rich identity platform. Historically, the most prevalent vulnerability classes include cross-site scripting and privilege escalation flaws, often stemming from improper input validation or insufficient access controls within its web interface. While no catastrophic, widespread data breaches have been publicly attributed to these specific CVEs, the high volume of findings indicates a need for rigorous patch management. The software’s open-source nature allows for community-driven security reviews, yet the frequency of issues suggests that continuous integration testing and code review processes remain essential for maintaining system integrity against potential exploitation.

Top products by goauthentik: authentik
CVE ID Title CVSS Severity Published
CVE-2026-94606 authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage — authentik CWE-287 8.9 High 2026-09-24
CVE-2026-94609 authentik: Privilege Escalation to Superuser via Group Hierarchy — authentik CWE-269 8.8 High 2026-09-24
CVE-2026-94611 authentik: Stored credentials are readable with view permission alone — authentik CWE-200 8.1 High 2026-09-24
CVE-2026-94612 authentik: Authentication bypass via assertion confusion in SAML sources — authentik CWE-287 7.4 High 2026-09-24
CVE-2026-94613 authentik: Denial of Service via Document Type Declarations in SAML Messages — authentik CWE-770 7.5 High 2026-09-24
CVE-2026-57580 authentik: Account Takeover via SAML NameID Comment Truncation — authentik CWE-436 9.4 Critical 2026-08-18
CVE-2026-55106 authentik: Unauthenticated LDAP directory data disclosure — authentik CWE-862 5.3 Medium 2026-08-18
CVE-2026-61574 authentik RAC: access any endpoint via an unrelated application — authentik CWE-639 8.8 High 2026-08-18
CVE-2026-54730 authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView — authentik CWE-284 8.6 High 2026-08-18
CVE-2026-49448 authentik: SourceStage bypass via empty POST — authentik CWE-287 9.8 Critical 2026-06-02
CVE-2026-49443 authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API — authentik CWE-287 8.8 High 2026-06-02
CVE-2026-47201 authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user — authentik CWE-20 8.5 High 2026-06-02
CVE-2026-42849 authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover — authentik CWE-79 9.3 Critical 2026-06-02
CVE-2026-41569 authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints — authentik CWE-601 - - 2026-06-02
CVE-2026-41577 authentik: SAML source does not validate Conditions, timing, or audience on assertions — authentik CWE-345 - - 2026-06-02
CVE-2026-40172 authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser — authentik CWE-269 8.1 High 2026-05-22
CVE-2026-40166 authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/ — authentik CWE-200 - - 2026-05-22
CVE-2026-40165 authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation — authentik CWE-287 8.7 High 2026-05-20
CVE-2026-25922 authentik has a Signature Verification Bypass via SAML Assertion Wrapping — authentik CWE-287 8.8 High 2026-02-12
CVE-2026-25748 authentik has a forward authentication bypass with broken cookie — authentik CWE-287 8.6 High 2026-02-12
CVE-2026-25227 authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint — authentik CWE-94 9.1 Critical 2026-02-12
CVE-2025-64708 authentik invitation expiry is delayed by at least 5 minutes — authentik CWE-613 5.8 Medium 2025-11-19
CVE-2025-64521 authentik deactivated service accounts can authenticate to OAuth — authentik CWE-289 4.8 Medium 2025-11-19
CVE-2025-53942 authentik has an insufficient check for account active status during OAuth/SAML authentication — authentik CWE-269 7.0 - 2025-07-23
CVE-2025-52553 authentik has Insufficient Session verification for Remote Access Control endpoint access — authentik CWE-287 9.1AI Critical AI 2025-06-27
CVE-2025-29928 authentik's deletion of sessions did not revoke sessions when using database session storage — authentik CWE-384 8.0 High 2025-03-28
CVE-2024-11623 Stored XSS in authentik — authentik CWE-79 4.8 - 2025-02-04
CVE-2024-52287 authentik performs insufficient validation of OAuth scopes — authentik CWE-285 7.5AI High AI 2024-11-21
CVE-2024-52289 authentik has an insecure default configuration for OAuth2 Redirect URIs — authentik CWE-185 6.1AI Medium AI 2024-11-21
CVE-2024-52307 authentik allows a timing attack due to missing constant time comparison for metrics view — authentik CWE-208 9.1AI Critical AI 2024-11-21

This page lists every published CVE security advisory associated with goauthentik. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.