VYPR

Bitnami package

authentik

pkg:bitnami/authentik

Vulnerabilities (45)

  • CVE-2026-94613HigSep 24, 2026
    affected < 2026.2.7fixed 2026.2.7

    authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker han

  • CVE-2026-94612HigSep 24, 2026
    affected < 2026.2.7fixed 2026.2.7

    authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login r

  • CVE-2026-94611HigSep 24, 2026
    affected < 2026.2.7fixed 2026.2.7

    authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or

  • CVE-2026-94609HigSep 24, 2026
    affected < 2026.2.7fixed 2026.2.7

    authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permiss

  • CVE-2026-94606HigSep 24, 2026
    affected < 2026.2.7fixed 2026.2.7

    authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already establishe

  • CVE-2026-61574HigAug 18, 2026
    affected < 2026.2.6fixed 2026.2.6

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings t

  • CVE-2026-57580CriAug 18, 2026
    affected < 2026.2.6fixed 2026.2.6

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An

  • CVE-2026-55106MedAug 18, 2026
    affected < 2026.2.6fixed 2026.2.6

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, including an unauthenticated client,

  • CVE-2026-54730HigAug 18, 2026
    affected < 2026.2.6fixed 2026.2.6

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome E

  • CVE-2026-49448CriJun 2, 2026
    affected < 2025.12.6fixed 2025.12.6

    authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.

  • CVE-2026-49443HigJun 2, 2026
    affected < 2025.12.6fixed 2025.12.6

    authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has been patched in versions 2025.1

  • CVE-2026-47201HigJun 2, 2026
    affected < 2026.5.1fixed 2026.5.1

    authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a v

  • CVE-2026-42849CriJun 2, 2026
    affected < 2025.12.5fixed 2025.12.5

    authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the Autosub

  • CVE-2026-41569MedJun 2, 2026
    affected < 2026.2.3fixed 2026.2.3

    authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link can supply a wreply value on a

  • CVE-2026-41577HigJun 2, 2026
    affected < 2025.12.5fixed 2025.12.5

    authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored. This a

  • CVE-2026-40172HigMay 22, 2026
    affected < 2025.12.5fixed 2025.12.5

    authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_su

  • CVE-2026-40166HigMay 22, 2026
    affected < 2025.12.5fixed 2025.12.5

    authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they have previously authenticated

  • CVE-2026-40165HigMay 21, 2026
    affected < 2025.12.5fixed 2025.12.5

    authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it wa

  • CVE-2026-25922HigFeb 12, 2026
    affected < 2025.8.6fixed 2025.8.6

    authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificat

  • CVE-2026-25748HigFeb 12, 2026
    affected >= 2025.10.0, < 2025.12.4fixed 2025.12.4

    authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. Whe

Page 1 of 3