PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72537 Authentik Security CVE debrief

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account, including superusers, by provisioning a SCIM user that matches an existing local user by username. This vulnerability impacts organizations using Authentik Security authentik through version 2026.5.6, particularly those with sensitive user accounts or superusers. The vulnerability arises from the SCIM user ingest function adopting pre-existing local accounts by username without validating scope boundaries. An attacker can rewrite or delete any account, including the superuser, using only a limited provisioning credential. Organizations should be aware of this vulnerability and take steps to mitigate it by patching to a version above 2026.5.6 and restricting SCIM provisioning tokens.

Vendor
Authentik Security
Product
authentik
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-03
Advisory published
2026-08-11
Advisory updated
2026-09-03

Who should care

Organizations using Authentik Security authentik through version 2026.5.6, especially those with sensitive user accounts or superusers, should be aware of this vulnerability and take steps to mitigate it. They should prioritize patching to prevent potential privilege escalation attacks and implement additional authentication and authorization controls for sensitive accounts. Conducting regular security audits and vulnerability assessments is also recommended to identify and address potential security risks. Additionally, monitoring user account provisioning and authentication events for suspicious activity can help detect and respond to potential security incidents. Implementing compensating controls for exposed systems while remediation is scheduled and verified can also help minimize the risk of exploitation. Reviewing and updating incident response plans to address this type of vulnerability is also essential. Asset inventory management and source tracking can help identify and prioritize remediation efforts. Rolling back changes and verifying remediation can also be necessary steps in the incident response process. Overall, a comprehensive security approach that includes patching, monitoring, and incident response planning is necessary to address this vulnerability effectively. This may involve coordination with Authentik Security and relevant stakeholders to ensure effective mitigation and remediation of the vulnerability. The vulnerability's impact on an organization's security posture should be carefully assessed and addressed through a combination of technical and procedural measures. The organization's vulnerability management and security teams should be engaged to ensure that the necessary steps are taken to mitigate the vulnerability and minimize potential risks. The vulnerability should be prioritized based on its severity and potential impact on the organization's security posture. The organization's security controls and incident response plans should be reviewed and updated to address this type of vulnerability. The necessary steps should be taken to ensure that the vulnerability is properly mitigated and that the organization's security posture,

Technical summary

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account, including superusers, by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. This allows an attacker to rewrite or delete any account, including the superuser, using only a limited provisioning credential. The vulnerability impacts organizations using Authentik Security authentik through version 2026.5.6. To mitigate this vulnerability, organizations should patch Authentik Security authentik to a version above 2026.5.6 and restrict SCIM provisioning tokens to prevent unauthorized account creation.

Defensive priority

Organizations using Authentik Security authentik through version 2026.5.6 should prioritize patching to prevent potential privilege escalation attacks.

Recommended defensive actions

  • Patch Authentik Security authentik to version above 2026.5.6
  • Restrict SCIM provisioning tokens to prevent unauthorized account creation
  • Monitor user account provisioning and authentication events for suspicious activity
  • Implement additional authentication and authorization controls for sensitive accounts
  • Conduct regular security audits and vulnerability assessments

Evidence notes

The CVE description indicates a privilege escalation vulnerability in Authentik Security authentik through 2026.5.6. An attacker with a source-scoped SCIM provisioning token can take over any user account, including superusers, by provisioning a SCIM user matching an existing local user by username.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72537 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72537

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72537 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72537

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/goauthentik/authentik

    309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.