PatchSiren cyber security CVE debrief
CVE-2026-94606 goauthentik CVE debrief
CVE-2026-94606 is a high-severity vulnerability in authentik, an open-source identity provider. The issue allows an attacker who knows a target user's password to enroll an email authenticator factor on behalf of the target, potentially leading to unauthorized access to single sign-on applications. This vulnerability is fixed in authentik versions 2026.2.7, 2026.5.7, and 2026.8.2.
- Vendor
- goauthentik
- Product
- authentik
- CVSS
- HIGH 8.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for authentik deployments, identity and access management, and single sign-on applications should assess exposure and prioritize verification and remediation efforts.
Why it matters
CVE-2026-94606 is a high-severity vulnerability in authentik that allows attackers to enroll an email authenticator factor on behalf of a target user, potentially leading to unauthorized access. Defenders should prioritize verifying and upgrading to fixed versions, assessing exposure, and monitoring for suspicious activities.
- Potential unauthorized access to single sign-on applications
- Elevation of privileges for attackers who know a target user's password
- Compromise of target user sessions
- Need for verification of authentik version and exposure
Technical summary
The vulnerability allows an attacker who knows a target user's password to substitute an attacker-controlled email address during the email authenticator enrollment process. This can lead to the attacker receiving a one-time code and finishing the enrollment process as the target, effectively gaining a session as the target and access to single sign-on applications. The target must not have enrolled the email factor already. Successful enrollment gives the actor a session as the target and access to single sign-on applications behind the account. Other authenticator types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Defensive priority
Defenders should prioritize verifying and upgrading to fixed versions of authentik, assessing exposure, and monitoring for suspicious enrollment activities.
Recommended defensive actions
- Verify and upgrade to fixed versions of authentik (2026.2.7, 2026.5.7, or 2026.8.2)
- Assess exposure and monitor for suspicious enrollment activities
- Implement additional authentication and authorization controls
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and fixed versions. However, the corpus does not establish evidence of exploitation or specific victim organizations. Defenders should verify authentik versions, assess exposure, and monitor for suspicious activities. The vulnerability allows an attacker who knows a target user's password to substitute an attacker-controlled email address during the email authenticator enrollment process. Successful enrollment gives the actor a session as the target and to
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94606 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94606
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94606 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94606
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.goauthentik.io/releases/2026.2
-
Source reference
Unverified legacy reference
URL: https://docs.goauthentik.io/releases/2026.5
-
Source reference
Unverified legacy reference
URL: https://docs.goauthentik.io/releases/2026.8
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/commit/01d4349f2aaa9beda532f92e2a251a17fefee9b3
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/commit/1fcf9868133e5d05e266edbc1f6f3ee972baa3f9
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/commit/c10ae83ebf8c61de2f1922edf1fab504d9f3b06f
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/commit/ec41732339726fba477182c0906a8d930b145beb
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/pull/25958
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.