8.9 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): Low (L)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
3 packages
- authentik-outposts.ldap
- authentik-outposts.proxy
- authentik-outposts.radius
- @LeSuisse accepted
- @LeSuisse published on GitHub
authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a target user's password can substitute an attacker-controlled address, receive the one-time code, and finish enrolling the factor as the target. The target must not have enrolled the email factor already. Successful enrollment gives the actor a session as the target and access to single sign-on applications behind the account. Other authenticator types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
References
-
https://github.com/goauthentik/authentik/security/advisories/GHSA-qgqp-xh8r-v73r x_refsource_CONFIRM
-
https://github.com/goauthentik/authentik/pull/25958 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25963 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25968 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25973 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.2#fixed-in-202627 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682 x_refsource_MISC
Affected products
- ==>= 2026.8.0, < 2026.8.2
- ==< 2026.2.7
- ==>= 2026.5.0, < 2026.5.7
Matching in nixpkgs
Ignored packages (3)
pkgs.authentik-outposts.ldap
Authentik ldap outpost. Needed for the external ldap API
pkgs.authentik-outposts.proxy
Authentik proxy outpost which is used for HTTP reverse proxy authentication
pkgs.authentik-outposts.radius
Authentik radius outpost which is used for the external radius API
Package maintainers
-
@jvanbruegge Jan van Brügge <supermanitu@gmail.com>
-
@rissson Marc Schmitt <marc.schmitt@risson.space>
7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
3 packages
- authentik-outposts.ldap
- authentik-outposts.proxy
- authentik-outposts.radius
- @LeSuisse accepted
- @LeSuisse published on GitHub
authentik: Denial of Service via Document Type Declarations in SAML Messages
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or /source/saml/*, causing the requests assigned to that worker to fail. Worker process termination and automatic restart do not destroy database-backed sessions, but continued malicious messages can cause a sustained share of legitimate traffic to fail. Other protocol implementations are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
References
-
https://github.com/goauthentik/authentik/security/advisories/GHSA-cxwx-9x59-28qm x_refsource_CONFIRM
-
https://github.com/goauthentik/authentik/pull/25959 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25964 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25969 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25974 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.2#fixed-in-202627 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682 x_refsource_MISC
Affected products
- ==>= 2026.8.0, < 2026.8.2
- ==>= 2026.5.0, < 2026.5.7
- ==< 2026.2.7
Matching in nixpkgs
Ignored packages (3)
pkgs.authentik-outposts.ldap
Authentik ldap outpost. Needed for the external ldap API
pkgs.authentik-outposts.proxy
Authentik proxy outpost which is used for HTTP reverse proxy authentication
pkgs.authentik-outposts.radius
Authentik radius outpost which is used for the external radius API
Package maintainers
-
@jvanbruegge Jan van Brügge <supermanitu@gmail.com>
-
@rissson Marc Schmitt <marc.schmitt@risson.space>
8.1 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
3 packages
- authentik-outposts.ldap
- authentik-outposts.proxy
- authentik-outposts.radius
- @LeSuisse accepted
- @LeSuisse published on GitHub
authentik: Stored credentials are readable with view permission alone
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications using a client or shared secret, and applications using a proxy provider. Deployments are affected when view permission is granted to accounts that are not intended to read these credentials; deployments where every viewer is permitted to read them are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
References
-
https://github.com/goauthentik/authentik/security/advisories/GHSA-m9h4-7j9c-55x9 x_refsource_CONFIRM
-
https://github.com/goauthentik/authentik/pull/25955 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25960 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25965 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25970 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.2#fixed-in-202627 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682 x_refsource_MISC
Affected products
- ==>= 2026.8.0, < 2026.8.2
- ==>= 2026.5.0, < 2026.5.7
- ==< 2026.2.7
Matching in nixpkgs
Ignored packages (3)
pkgs.authentik-outposts.ldap
Authentik ldap outpost. Needed for the external ldap API
pkgs.authentik-outposts.proxy
Authentik proxy outpost which is used for HTTP reverse proxy authentication
pkgs.authentik-outposts.radius
Authentik radius outpost which is used for the external radius API
Package maintainers
-
@jvanbruegge Jan van Brügge <supermanitu@gmail.com>
-
@rissson Marc Schmitt <marc.schmitt@risson.space>
8.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
3 packages
- authentik-outposts.ldap
- authentik-outposts.proxy
- authentik-outposts.radius
- @LeSuisse accepted
- @LeSuisse published on GitHub
authentik: Privilege Escalation to Superuser via Group Hierarchy
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
References
-
https://github.com/goauthentik/authentik/security/advisories/GHSA-h6c5-mpvq-j4jc x_refsource_CONFIRM
-
https://github.com/goauthentik/authentik/pull/25956 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25961 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25966 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25971 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.2#fixed-in-202627 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682 x_refsource_MISC
Affected products
- ==>= 2026.8.0, < 2026.8.2
- ==< 2026.2.7
- ==>= 2026.5.0, < 2026.5.7
Matching in nixpkgs
Ignored packages (3)
pkgs.authentik-outposts.ldap
Authentik ldap outpost. Needed for the external ldap API
pkgs.authentik-outposts.proxy
Authentik proxy outpost which is used for HTTP reverse proxy authentication
pkgs.authentik-outposts.radius
Authentik radius outpost which is used for the external radius API
Package maintainers
-
@jvanbruegge Jan van Brügge <supermanitu@gmail.com>
-
@rissson Marc Schmitt <marc.schmitt@risson.space>
7.4 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
3 packages
- authentik-outposts.ldap
- authentik-outposts.proxy
- authentik-outposts.radius
- @LeSuisse accepted
- @LeSuisse published on GitHub
authentik: Authentication bypass via assertion confusion in SAML sources
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML Source also does not record already accepted assertions, allowing replay. An unauthenticated actor who possesses such a valid assertion can use an assertion intended for another service provider or reuse an earlier assertion to authenticate as the user named by the assertion. Only SAML Sources are affected; SAML Providers and other Source types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
References
-
https://github.com/goauthentik/authentik/security/advisories/GHSA-cqj8-fxxf-9pg7 x_refsource_CONFIRM
-
https://github.com/goauthentik/authentik/pull/25957 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25962 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25967 x_refsource_MISC
-
https://github.com/goauthentik/authentik/pull/25972 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.2#fixed-in-202627 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657 x_refsource_MISC
-
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682 x_refsource_MISC
Affected products
- ==>= 2026.8.0, < 2026.8.2
- ==< 2026.2.7
- ==>= 2026.5.0, < 2026.5.7
Matching in nixpkgs
Ignored packages (3)
pkgs.authentik-outposts.ldap
Authentik ldap outpost. Needed for the external ldap API
pkgs.authentik-outposts.proxy
Authentik proxy outpost which is used for HTTP reverse proxy authentication
pkgs.authentik-outposts.radius
Authentik radius outpost which is used for the external radius API
Package maintainers
-
@jvanbruegge Jan van Brügge <supermanitu@gmail.com>
-
@rissson Marc Schmitt <marc.schmitt@risson.space>