7.4

CVE-2026-94612

authentik: Authentication bypass via assertion confusion in SAML sources

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML Source also does not record already accepted assertions, allowing replay. An unauthenticated actor who possesses such a valid assertion can use an assertion intended for another service provider or reuse an earlier assertion to authenticate as the user named by the assertion. Only SAML Sources are affected; SAML Providers and other Source types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellergoauthentik
≫
Produkt authentik
Version < 2026.2.7
Status affected
Version >= 2026.5.0, < 2026.5.7
Status affected
Version >= 2026.8.0, < 2026.8.2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.168
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

https://docs.goauthentik.io/releases/2026.2#fixed-in-202627
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682
https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2
https://github.com/goauthentik/authentik/security/advisories/GHSA-cqj8-fxxf-9pg7
https://github.com/goauthentik/authentik/pull/25957
https://github.com/goauthentik/authentik/pull/25962
https://github.com/goauthentik/authentik/pull/25967
https://github.com/goauthentik/authentik/pull/25972
https://github.com/goauthentik/authentik/commit/287ea13cdc23c378abc20a7b71c9c7919a19a89a
https://github.com/goauthentik/authentik/commit/355d8cc3d755fbba05fc5fa90ffbcbe6469acddd
https://github.com/goauthentik/authentik/commit/54fac864a0b3bc00551af1908f662b3bf5cc6135
https://github.com/goauthentik/authentik/commit/984b0162711f0d1988ed33544d0a671c93e4ec76