CVE-2026-40172
- EPSS 0.54%
- Veröffentlicht 22.05.2026 19:00:52
- Zuletzt bearbeitet 23.07.2026 16:10:00
authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerialize...
CVE-2026-40166
- EPSS 0.46%
- Veröffentlicht 22.05.2026 18:52:46
- Zuletzt bearbeitet 23.07.2026 16:10:00
authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they ...
CVE-2026-40165
- EPSS 0.5%
- Veröffentlicht 20.05.2026 23:35:18
- Zuletzt bearbeitet 23.07.2026 15:10:00
authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID valu...
CVE-2026-25922
- EPSS 0.23%
- Veröffentlicht 12.02.2026 19:38:16
- Zuletzt bearbeitet 18.02.2026 20:59:27
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not ...
CVE-2026-25748
- EPSS 0.61%
- Veröffentlicht 12.02.2026 19:36:45
- Zuletzt bearbeitet 19.02.2026 15:23:42
authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik ...
CVE-2026-25227
- EPSS 0.8%
- Veröffentlicht 12.02.2026 19:25:26
- Zuletzt bearbeitet 19.02.2026 15:25:12
authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute a...
CVE-2025-64708
- EPSS 0.25%
- Veröffentlicht 19.11.2025 17:15:52
- Zuletzt bearbeitet 20.11.2025 18:56:40
authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are expired or not, thus relying on background tasks to clean up expired one...
CVE-2025-64521
- EPSS 0.22%
- Veröffentlicht 19.11.2025 17:15:52
- Zuletzt bearbeitet 20.11.2025 18:56:52
authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, ...
CVE-2025-53942
- EPSS 0.49%
- Veröffentlicht 23.07.2025 20:35:07
- Zuletzt bearbeitet 21.08.2025 18:35:27
authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered...
CVE-2025-52553
- EPSS 0.44%
- Veröffentlicht 27.06.2025 15:15:25
- Zuletzt bearbeitet 21.08.2025 18:39:24
authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session o...