8.8

CVE-2026-25922

authentik has a Signature Verification Bypass via SAML Assertion Wrapping

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificate setting under Advanced Protocol settings configured, it was possible for an attacker to inject a malicious assertion before the signed assertion that authentik would use instead. authentik 2025.8.6, 2025.10.4, and 2025.12.4 fix this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoauthentikAuthentik Version < 2025.8.6
GoauthentikAuthentik Version >= 2025.10.0 < 2025.10.4
GoauthentikAuthentik Version >= 2025.12.0 < 2025.12.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://github.com/goauthentik/authentik/releases/tag/version%2F2025.10.4
Product
Release Notes
https://github.com/goauthentik/authentik/releases/tag/version%2F2025.12.4
Product
Release Notes
https://github.com/goauthentik/authentik/releases/tag/version%2F2025.8.6
Product
Release Notes
https://github.com/goauthentik/authentik/security/advisories/GHSA-jh35-c4cc-wjm4
Vendor Advisory
Mitigation