Goauthentik
Goauthentik Authentik: vulnerabilidades y CVE
Goauthentik Authentik tiene 48 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE48
Últimos 12 meses26
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94613 | Alta (7.5) | 0.64% | — | 24 sept 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the… |
| CVE-2026-94612 | Alta (7.4) | 0.27% | — | 24 sept 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider… |
| CVE-2026-94611 | Alta (8.1) | 0.33% | — | 24 sept 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when… |
| CVE-2026-94609 | Alta (8.8) | 0.51% | — | 24 sept 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or… |
| CVE-2026-94606 | Alta (8.9) | 0.49% | — | 24 sept 2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the… |
| CVE-2026-61574 | Alta (8.8) | 0.62% | — | 18 ago 2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the… |
| CVE-2026-57580 | Crítica (9.4) | 0.59% | — | 18 ago 2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID… |
| CVE-2026-55106 | Media (5.3) | 0.44% | — | 18 ago 2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any… |
| CVE-2026-54730 | Alta (8.6) | 0.68% | — | 18 ago 2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran.… |
| CVE-2026-72537 | Alta (8.8) | 0.40% | — | 11 ago 2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a… |
| CVE-2026-72534 | Alta (8.8) | 0.42% | — | 11 ago 2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that… |
| CVE-2026-49448 | Crítica (9.8) | 0.58% | — | 2 jun 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4,… |
| CVE-2026-49443 | Alta (8.8) | 0.44% | — | 2 jun 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log… |
| CVE-2026-47201 | Alta (8.5) | 0.28% | — | 2 jun 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses.… |
| CVE-2026-42849 | Crítica (9.3) | 0.47% | — | 2 jun 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy… |
| CVE-2026-41569 | Media (6.9) | 0.32% | — | 2 jun 2026 | authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An… |
| CVE-2026-41577 | Media (6.9) | 0.19% | — | 2 jun 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore,… |
| CVE-2026-44649 | Crítica (9.8) | 0.29% | — | 29 may 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts… |
| CVE-2026-40172 | Alta (8.1) | 0.72% | — | 22 may 2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign… |
| CVE-2026-40166 | Alta (7.1) | 0.56% | — | 22 may 2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of… |
| CVE-2026-40165 | Alta (8.7) | 0.68% | — | 21 may 2026 | authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how… |
| CVE-2026-25922 | Alta (8.8) | 0.31% | — | 12 feb 2026 | authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify… |
| CVE-2026-25748 | Alta (7.5) | 0.78% | — | 12 feb 2026 | authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when… |
| CVE-2026-25227 | Alta (7.2) | 0.83% | — | 12 feb 2026 | authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view… |
| CVE-2025-64708 | Media (5.3) | 0.25% | — | 19 nov 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are expired or not, thus relying on… |
| CVE-2025-64521 | Media (4.8) | 0.22% | — | 19 nov 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider.… |
| CVE-2025-53942 | Alta (7.1) | 0.53% | — | 23 jul 2025 | authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3,… |
| CVE-2025-52553 | Media (5.5) | 0.52% | — | 27 jun 2025 | authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to… |
| CVE-2025-29928 | Alta (8) | 0.39% | — | 28 mar 2025 | authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the… |
| CVE-2024-11623 | Media (4.8) | 0.30% | — | 4 feb 2025 | Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.