VYPR

Vendor CVEs

authentik

All CVEs

45 total · sorted by risk
  • CVE-2022-23555CriDec 28, 2022
    risk 0.61cvss 9.4epss 0.01

    authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow…

  • CVE-2023-26481CriMar 4, 2023
    risk 0.59cvss 9.1epss 0.00

    authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user. This attack is only possible if a recovery flow exists,…

  • CVE-2026-61574HigAug 18, 2026
    risk 0.57cvss 8.8epss

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings…

  • CVE-2026-72537HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username.…

  • CVE-2026-72534HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group…

  • CVE-2026-49448CriJun 2, 2026
    risk 0.57cvss 9.8epss 0.00

    authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.

  • CVE-2026-25922HigFeb 12, 2026
    risk 0.57cvss 8.8epss 0.00

    authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption…

  • CVE-2024-37905HigJun 28, 2024
    risk 0.57cvss 8.8epss 0.01

    authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik…

  • CVE-2026-25748HigFeb 12, 2026
    risk 0.56cvss 8.6epss 0.01

    authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy.…

  • CVE-2024-38371HigJun 28, 2024
    risk 0.56cvss 8.6epss 0.01

    authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This…

  • CVE-2026-57580CriAug 18, 2026
    risk 0.54cvss epss

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion.…

  • CVE-2026-42849CriJun 2, 2026
    risk 0.53cvss 9.3epss 0.00

    authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the…

  • CVE-2022-46145HigDec 2, 2022
    risk 0.53cvss 8.1epss 0.01

    authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows…

  • CVE-2026-49443HigJun 2, 2026
    risk 0.50cvss 8.8epss 0.00

    authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has been patched in versions…

  • CVE-2026-40165HigMay 21, 2026
    risk 0.50cvss 8.7epss 0.01

    authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it…

  • CVE-2026-54730HigAug 18, 2026
    risk 0.49cvss epss

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome…

  • CVE-2024-21637HigJan 11, 2024
    risk 0.49cvss 7.6epss 0.01

    Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This relatively user could use the described attacks to perform a privilege…

  • CVE-2026-47201HigJun 2, 2026
    risk 0.48cvss 8.5epss 0.00

    authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a…

  • CVE-2026-40172HigMay 22, 2026
    risk 0.46cvss 8.1epss 0.01

    authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with…

  • CVE-2026-41577HigJun 2, 2026
    risk 0.42cvss 7.5epss 0.00

    authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored. This…

  • CVE-2024-42490HigAug 22, 2024
    risk 0.42cvss 7.5epss 0.00

    authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs//view_certificate/,…

  • CVE-2022-46172MedDec 28, 2022
    risk 0.42cvss 6.4epss 0.01

    authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where…

  • CVE-2025-53942HigJul 23, 2025
    risk 0.41cvss 7.4epss 0.00

    authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered through OAuth/SAML or linked…

  • CVE-2026-40166HigMay 22, 2026
    risk 0.39cvss epss 0.00

    authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they have previously authenticated…

  • CVE-2024-23647MedJan 30, 2024
    risk 0.35cvss 6.5epss 0.01

    Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_verifier parameter to the…

  • CVE-2026-41569MedJun 2, 2026
    risk 0.33cvss 6.1epss 0.00

    authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link can supply a wreply value on a…

  • CVE-2025-64708MedNov 19, 2025
    risk 0.31cvss 5.8epss 0.00

    authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are expired or not, thus relying on background tasks to clean up expired ones. In a normal scenario this…

  • CVE-2026-55106MedAug 18, 2026
    risk 0.27cvss 5.3epss

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, including an unauthenticated…

  • CVE-2023-39522MedAug 29, 2023
    risk 0.27cvss 5.3epss 0.01

    goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a…

  • CVE-2025-64521MedNov 19, 2025
    risk 0.24cvss 4.8epss 0.00

    authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this…

  • CVE-2008-1174Mar 6, 2008
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter.

  • CVE-2026-25227CriFeb 12, 2026
    risk 0.00cvss 9.1epss 0.01

    authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the…

  • CVE-2025-52553CriJun 27, 2025
    risk 0.00cvss 9.6epss 0.00

    authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session of the user who authorized the…

  • CVE-2025-29928HigMar 28, 2025
    risk 0.00cvss 8.0epss 0.00

    authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would not revoke the session and…

  • CVE-2024-11623MedFeb 4, 2025
    risk 0.00cvss 4.8epss 0.00

    Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.  This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.

  • CVE-2024-52307MedNov 21, 2024
    risk 0.00cvss 5.6epss 0.01

    authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the SECRET_KEY, which is used to authenticate the endpoint. The /-/metrics/ endpoint returns Prometheus metrics and is…

  • CVE-2024-52289CriNov 21, 2024
    risk 0.00cvss 9.8epss 0.01

    authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value received as an allowed redirect…

  • CVE-2024-52287HigNov 21, 2024
    risk 0.00cvss 7.2epss 0.01

    authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.

  • CVE-2024-47077MedSep 27, 2024
    risk 0.00cvss 6.5epss 0.00

    authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were…

  • CVE-2024-47070CriSep 27, 2024
    risk 0.00cvss 9.0epss 0.01

    authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any…

  • CVE-2023-48228HigNov 21, 2023
    risk 0.00cvss 7.5epss 0.01

    authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during the token step. Prior to…

  • CVE-2023-46249CriOct 31, 2023
    risk 0.00cvss 9.6epss 0.01

    authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint…

  • CVE-2023-36456HigJul 6, 2023
    risk 0.00cvss 8.3epss 0.01

    authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and the go code. Only authentik setups that are directly accessible by users without…

  • CVE-2008-1175Mar 6, 2008
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter to aspAdmin/deleteUser.asp, a different vector than CVE-2008-1174. NOTE: the provenance of this information is unknown;…

  • CVE-2000-1133Jan 9, 2001
    risk 0.00cvss epss 0.02

    Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.