8.1
CVE-2026-94611
- EPSS 0.33%
- Veröffentlicht 24.09.2026 16:18:46
- Zuletzt bearbeitet 24.09.2026 19:39:45
- Erkennungen
authentik: Stored credentials are readable with view permission alone
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications using a client or shared secret, and applications using a proxy provider. Deployments are affected when view permission is granted to accounts that are not intended to read these credentials; deployments where every viewer is permitted to read them are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellergoauthentik
≫
Produkt
authentik
Version
< 2026.2.7
Status
affected
Version
>= 2026.5.0, < 2026.5.7
Status
affected
Version
>= 2026.8.0, < 2026.8.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.24 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://docs.goauthentik.io/releases/2026.2#fixed-in-202627
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682
https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2
https://github.com/goauthentik/authentik/security/advisories/GHSA-m9h4-7j9c-55x9
https://github.com/goauthentik/authentik/pull/25955
https://github.com/goauthentik/authentik/pull/25960
https://github.com/goauthentik/authentik/pull/25965
https://github.com/goauthentik/authentik/pull/25970
https://github.com/goauthentik/authentik/commit/4b3fad38be44ef3eef1f0baf83e7b3061229eb99
https://github.com/goauthentik/authentik/commit/5109a4d4998d6a5ee399ca3e22ba546231c140c7
https://github.com/goauthentik/authentik/commit/6bed64ef80a4dd21011cce64c41b1e7c5640ecb3
https://github.com/goauthentik/authentik/commit/77d2e24442c3eb6e88010f40aa569a8bfb584f99