8.1

CVE-2026-94611

authentik: Stored credentials are readable with view permission alone

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications using a client or shared secret, and applications using a proxy provider. Deployments are affected when view permission is granted to accounts that are not intended to read these credentials; deployments where every viewer is permitted to read them are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellergoauthentik
≫
Produkt authentik
Version < 2026.2.7
Status affected
Version >= 2026.5.0, < 2026.5.7
Status affected
Version >= 2026.8.0, < 2026.8.2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.24
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://docs.goauthentik.io/releases/2026.2#fixed-in-202627
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682
https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2
https://github.com/goauthentik/authentik/security/advisories/GHSA-m9h4-7j9c-55x9
https://github.com/goauthentik/authentik/pull/25955
https://github.com/goauthentik/authentik/pull/25960
https://github.com/goauthentik/authentik/pull/25965
https://github.com/goauthentik/authentik/pull/25970
https://github.com/goauthentik/authentik/commit/4b3fad38be44ef3eef1f0baf83e7b3061229eb99
https://github.com/goauthentik/authentik/commit/5109a4d4998d6a5ee399ca3e22ba546231c140c7
https://github.com/goauthentik/authentik/commit/6bed64ef80a4dd21011cce64c41b1e7c5640ecb3
https://github.com/goauthentik/authentik/commit/77d2e24442c3eb6e88010f40aa569a8bfb584f99