Authentik
Goauthentik · 45 CVEs
authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage
Sep 24, 2026
authentik: Privilege Escalation to Superuser via Group Hierarchy
Sep 24, 2026
authentik: Stored credentials are readable with view permission alone
Sep 24, 2026
authentik: Authentication bypass via assertion confusion in SAML sources
Sep 24, 2026
authentik: Denial of Service via Document Type Declarations in SAML Messages
Sep 24, 2026
authentik: Account Takeover via SAML NameID Comment Truncation
Aug 18, 2026
authentik: Unauthenticated LDAP directory data disclosure
Aug 18, 2026
authentik RAC: access any endpoint via an unrelated application
Aug 18, 2026
authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChrom…
Aug 18, 2026
authentik: SourceStage bypass via empty POST
Jun 2, 2026
authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API
Jun 2, 2026
authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
Jun 2, 2026
authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover
Jun 2, 2026
authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints
Jun 2, 2026
authentik: SAML source does not validate Conditions, timing, or audience on assertions
Jun 2, 2026
authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser
May 22, 2026
authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/
May 22, 2026
authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation
May 20, 2026
authentik has a Signature Verification Bypass via SAML Assertion Wrapping
Feb 12, 2026
authentik has a forward authentication bypass with broken cookie
Feb 12, 2026
authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint
Feb 12, 2026
authentik invitation expiry is delayed by at least 5 minutes
Nov 19, 2025
authentik deactivated service accounts can authenticate to OAuth
Nov 19, 2025
authentik has an insufficient check for account active status during OAuth/SAML authentication
Jul 23, 2025
authentik has Insufficient Session verification for Remote Access Control endpoint access
Jun 27, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-94606 | authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage | HIGH | 0.49% | Sep 24, 2026 |
| CVE-2026-94609 | authentik: Privilege Escalation to Superuser via Group Hierarchy | HIGH | 0.51% | Sep 24, 2026 |
| CVE-2026-94611 | authentik: Stored credentials are readable with view permission alone | HIGH | 0.33% | Sep 24, 2026 |
| CVE-2026-94612 | authentik: Authentication bypass via assertion confusion in SAML sources | HIGH | 0.27% | Sep 24, 2026 |
| CVE-2026-94613 | authentik: Denial of Service via Document Type Declarations in SAML Messages | HIGH | 0.64% | Sep 24, 2026 |
| CVE-2026-57580 | authentik: Account Takeover via SAML NameID Comment Truncation | CRITICAL | 0.59% | Aug 18, 2026 |
| CVE-2026-55106 | authentik: Unauthenticated LDAP directory data disclosure | MEDIUM | 0.44% | Aug 18, 2026 |
| CVE-2026-61574 | authentik RAC: access any endpoint via an unrelated application | HIGH | 0.62% | Aug 18, 2026 |
| CVE-2026-54730 | authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView | HIGH | 0.68% | Aug 18, 2026 |
| CVE-2026-49448 | authentik: SourceStage bypass via empty POST | CRITICAL | 0.58% | Jun 2, 2026 |
| CVE-2026-49443 | authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API | HIGH | 0.44% | Jun 2, 2026 |
| CVE-2026-47201 | authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user | HIGH | 0.28% | Jun 2, 2026 |
| CVE-2026-42849 | authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover | CRITICAL | 0.47% | Jun 2, 2026 |
| CVE-2026-41569 | authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints | MEDIUM | 0.32% | Jun 2, 2026 |
| CVE-2026-41577 | authentik: SAML source does not validate Conditions, timing, or audience on assertions | MEDIUM | 0.19% | Jun 2, 2026 |
| CVE-2026-40172 | authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser | HIGH | 0.72% | May 22, 2026 |
| CVE-2026-40166 | authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/ | HIGH | 0.56% | May 22, 2026 |
| CVE-2026-40165 | authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation | HIGH | 0.68% | May 20, 2026 |
| CVE-2026-25922 | authentik has a Signature Verification Bypass via SAML Assertion Wrapping | HIGH | 0.31% | Feb 12, 2026 |
| CVE-2026-25748 | authentik has a forward authentication bypass with broken cookie | HIGH | 0.78% | Feb 12, 2026 |
| CVE-2026-25227 | authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint | CRITICAL | 0.83% | Feb 12, 2026 |
| CVE-2025-64708 | authentik invitation expiry is delayed by at least 5 minutes | MEDIUM | 0.25% | Nov 19, 2025 |
| CVE-2025-64521 | authentik deactivated service accounts can authenticate to OAuth | MEDIUM | 0.22% | Nov 19, 2025 |
| CVE-2025-53942 | authentik has an insufficient check for account active status during OAuth/SAML authentication | HIGH | 0.53% | Jul 23, 2025 |
| CVE-2025-52553 | authentik has Insufficient Session verification for Remote Access Control endpoint access | MEDIUM | 0.52% | Jun 27, 2025 |
Showing 1 to 25 of 45 CVEs