Skip to main content

Vendor/product archive

goauthentik / authentik CVEs

Beta · best-effort

33 CVEs tagged to goauthentik / authentik7 Critical, 14 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2026-49448

Published Jun 2, 2026

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49443

Published Jun 2, 2026

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in o…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47201

Published Jun 2, 2026

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping wh…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42849

Published Jun 2, 2026

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41569

Published Jun 2, 2026

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check r…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41577

Published Jun 2, 2026

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Condi…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25922

Published Feb 12, 2026

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verificat…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-25748

Published Feb 12, 2026

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25227

Published Feb 12, 2026

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can vie…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2025-64708

Published Nov 19, 2025

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are e…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64521

Published Nov 19, 2025

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creat…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53942

Published Jul 23, 2025

authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52553

Published Jun 27, 2025

authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the clien…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-29928

Published Mar 28, 2025

authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-defa…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11623

Published Feb 4, 2025

Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.  This action could only be performed by an authentica…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52307

Published Nov 21, 2024

authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the SECRET_KEY, which…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52289

Published Nov 21, 2024

authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provide…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52287

Published Nov 21, 2024

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with sc…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47077

Published Sep 27, 2024

authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to imper…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47070

Published Sep 27, 2024

authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For hea…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-42490

Published Aug 22, 2024

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38371

Published Jun 28, 2024

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37905

Published Jun 28, 2024

authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23647

Published Jan 30, 2024

Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the co…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21637

Published Jan 11, 2024

Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `respon…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2