« Volver al listado

CVE-2026-47201

Estado: AnalizadaAlta (8.5)—

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue has been patched in versions 2025.12.5, 2026.2.3, and 2026.5.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

SAML XML Signature Wrapping permite reutilizar aserciones firmadas válidas para autenticarse como otro usuario federado (T1078). Requiere privilegios previos en el IdP aguas arriba (PR:L) y acceso de red (AV:N), compatible con T1210. El atacante obtiene cuentas/identidades falsas (impacto T1078) y p

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-47201",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-47201",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-03T13:56:09.745826Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "goauthentik",
          "product": "authentik",
          "versions": [
            {
              "status": "affected",
              "version": "< 2025.12.5"
            },
            {
              "status": "affected",
              "version": "< 2026.2.3"
            },
            {
              "status": "affected",
              "version": "< 2026.5.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-02T21:16:27.940",
  "references": [
    {
      "url": "https://github.com/goauthentik/authentik/security/advisories/GHSA-c3m2-jqmq-pvp3",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue has been patched in versions 2025.12.5, 2026.2.3, and 2026.5.1."
    },
    {
      "lang": "es",
      "value": "authentik es un proveedor de identidad de código abierto. Antes de las versiones 2025.12.5, 2026.2.3 y 2026.5.1, el endpoint ACS de la fuente SAML de authentik es vulnerable a la envoltura de firma XML al validar respuestas SAML ascendentes. Un atacante con cualquier cuenta en el IdP ascendente puede reutilizar una aserción firmada válida para autenticarse como otro usuario federado. Este problema ha sido parcheado en las versiones 2025.12.5, 2026.2.3 y 2026.5.1."
    }
  ],
  "lastModified": "2026-07-22T19:10:00.120",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2248E771-C089-49F8-B370-D3E089534A60",
              "versionEndExcluding": "2025.12.6"
            },
            {
              "criteria": "cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2723A03F-6FA5-40D6-9D67-320CBC6538C4",
              "versionEndExcluding": "2026.2.4",
              "versionStartIncluding": "2026.2.0"
            },
            {
              "criteria": "cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D092DE78-A8F3-4569-80F8-0289DF27CB2D",
              "versionEndExcluding": "2026.5.1",
              "versionStartIncluding": "2026.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}