Back

MEDIUM

authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints

Published Jun 2, 2026

Description

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link can supply a wreply value on a different origin that passes the check (e.g. https://portal.example.com.evil.tld/), causing the victim's browser to POST the signed WS-Federation login response to attacker-controlled infrastructure. This issue has been patched in version 2026.2.3.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 2, 2026
Updated Jun 3, 2026
Reserved Apr 21, 2026
CISA Vulnrichment
Updated Jun 3, 2026
NVD
Status Analyzed
Modified Jul 22, 2026
Red Hat
Severity n/a
Public date n/a