PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94606 goauthentik CVE debrief

CVE-2026-94606 is a high-severity vulnerability in authentik, an open-source identity provider. The issue allows an attacker who knows a target user's password to enroll an email authenticator factor on behalf of the target, potentially leading to unauthorized access to single sign-on applications. This vulnerability is fixed in authentik versions 2026.2.7, 2026.5.7, and 2026.8.2.

Vendor
goauthentik
Product
authentik
CVSS
HIGH 8.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-25
Advisory published
2026-09-24
Advisory updated
2026-09-25

Who should care

Defenders responsible for authentik deployments, identity and access management, and single sign-on applications should assess exposure and prioritize verification and remediation efforts.

Why it matters

CVE-2026-94606 is a high-severity vulnerability in authentik that allows attackers to enroll an email authenticator factor on behalf of a target user, potentially leading to unauthorized access. Defenders should prioritize verifying and upgrading to fixed versions, assessing exposure, and monitoring for suspicious activities.

  • Potential unauthorized access to single sign-on applications
  • Elevation of privileges for attackers who know a target user's password
  • Compromise of target user sessions
  • Need for verification of authentik version and exposure

Technical summary

The vulnerability allows an attacker who knows a target user's password to substitute an attacker-controlled email address during the email authenticator enrollment process. This can lead to the attacker receiving a one-time code and finishing the enrollment process as the target, effectively gaining a session as the target and access to single sign-on applications. The target must not have enrolled the email factor already. Successful enrollment gives the actor a session as the target and access to single sign-on applications behind the account. Other authenticator types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.

Defensive priority

Defenders should prioritize verifying and upgrading to fixed versions of authentik, assessing exposure, and monitoring for suspicious enrollment activities.

Recommended defensive actions

  • Verify and upgrade to fixed versions of authentik (2026.2.7, 2026.5.7, or 2026.8.2)
  • Assess exposure and monitor for suspicious enrollment activities
  • Implement additional authentication and authorization controls
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and fixed versions. However, the corpus does not establish evidence of exploitation or specific victim organizations. Defenders should verify authentik versions, assess exposure, and monitor for suspicious activities. The vulnerability allows an attacker who knows a target user's password to substitute an attacker-controlled email address during the email authenticator enrollment process. Successful enrollment gives the actor a session as the target and to

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94606 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94606

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94606 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94606

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.