Goauthentik

Authentik

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.36%
  • Veröffentlicht 02.06.2026 20:31:20
  • Zuletzt bearbeitet 04.06.2026 20:16:33

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 02.06.2026 20:31:09
  • Zuletzt bearbeitet 04.06.2026 20:16:00

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has b...

  • EPSS 0.16%
  • Veröffentlicht 02.06.2026 20:30:55
  • Zuletzt bearbeitet 04.06.2026 20:14:17

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at ...

  • EPSS 0.32%
  • Veröffentlicht 02.06.2026 20:30:43
  • Zuletzt bearbeitet 04.06.2026 20:01:26

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use...

  • EPSS 0.18%
  • Veröffentlicht 02.06.2026 20:30:21
  • Zuletzt bearbeitet 04.06.2026 20:00:32

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link c...

  • EPSS 0.17%
  • Veröffentlicht 02.06.2026 17:12:26
  • Zuletzt bearbeitet 04.06.2026 19:44:27

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestr...

  • EPSS 0.39%
  • Veröffentlicht 22.05.2026 19:00:52
  • Zuletzt bearbeitet 22.05.2026 19:00:52

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerialize...

  • EPSS 0.34%
  • Veröffentlicht 22.05.2026 18:52:46
  • Zuletzt bearbeitet 22.05.2026 18:52:46

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they ...

  • EPSS 0.39%
  • Veröffentlicht 20.05.2026 23:35:18
  • Zuletzt bearbeitet 21.05.2026 15:24:25

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID valu...

  • EPSS 0.17%
  • Veröffentlicht 12.02.2026 19:38:16
  • Zuletzt bearbeitet 18.02.2026 20:59:27

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not ...