8.8

CVE-2026-94609

authentik: Privilege Escalation to Superuser via Group Hierarchy

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellergoauthentik
≫
Produkt authentik
Version < 2026.2.7
Status affected
Version >= 2026.5.0, < 2026.5.7
Status affected
Version >= 2026.8.0, < 2026.8.2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.413
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://docs.goauthentik.io/releases/2026.2#fixed-in-202627
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682
https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2
https://github.com/goauthentik/authentik/security/advisories/GHSA-h6c5-mpvq-j4jc
https://github.com/goauthentik/authentik/pull/25956
https://github.com/goauthentik/authentik/pull/25961
https://github.com/goauthentik/authentik/pull/25966
https://github.com/goauthentik/authentik/pull/25971
https://github.com/goauthentik/authentik/commit/5f95b86f6f70c3bd8c625a4f9ae474e235f84030
https://github.com/goauthentik/authentik/commit/67317f66f1b7eb16f2a26bf550dfd73699d49d87
https://github.com/goauthentik/authentik/commit/67e470dde8c81a40ee27ec6e178462368c561a60
https://github.com/goauthentik/authentik/commit/898e4e4fa070642a3541a376af0de64fe3ffeb67