Goauthentik

Authentik

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 24.09.2026 16:23:30
  • Zuletzt bearbeitet 05.10.2026 16:17:17

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using ...

  • EPSS 0.51%
  • Veröffentlicht 24.09.2026 16:20:45
  • Zuletzt bearbeitet 28.09.2026 16:17:18

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a gro...

  • EPSS 0.33%
  • Veröffentlicht 24.09.2026 16:18:46
  • Zuletzt bearbeitet 24.09.2026 19:39:45

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized t...

  • EPSS 0.27%
  • Veröffentlicht 24.09.2026 16:16:33
  • Zuletzt bearbeitet 24.09.2026 19:39:45

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Sour...

  • EPSS 0.64%
  • Veröffentlicht 24.09.2026 16:13:17
  • Zuletzt bearbeitet 29.09.2026 03:17:21

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The m...

Medienbericht
  • EPSS 0.44%
  • Veröffentlicht 18.08.2026 17:00:19
  • Zuletzt bearbeitet 08.09.2026 21:02:26

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity p...

  • EPSS 0.25%
  • Veröffentlicht 18.08.2026 16:59:12
  • Zuletzt bearbeitet 08.09.2026 21:02:26

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, includ...

  • EPSS 0.36%
  • Veröffentlicht 18.08.2026 16:57:47
  • Zuletzt bearbeitet 08.09.2026 21:02:26

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response ...

  • EPSS 0.37%
  • Veröffentlicht 18.08.2026 16:55:29
  • Zuletzt bearbeitet 08.09.2026 21:02:26

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 02.06.2026 20:31:20
  • Zuletzt bearbeitet 22.07.2026 19:10:00

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.