PatchSiren cyber security CVE debrief
CVE-2026-94609 goauthentik CVE debrief
CVE-2026-94609 is a high-severity vulnerability in authentik, an open-source identity provider. The issue allows an account with delegated permission to manage a group, group membership, or a user to grant superuser status or assign an existing role without holding the required permissions. This affects deployments that delegate these capabilities to non-full administrators. The vulnerability is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
- Vendor
- goauthentik
- Product
- authentik
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for authentik deployments, especially those with delegated management capabilities, should assess their exposure and take necessary actions to mitigate the vulnerability.
Why it matters
CVE-2026-94609 is a high-severity vulnerability in authentik that allows unauthorized privilege escalation and role assignment. Defenders should verify exposure, especially in deployments with delegated management capabilities, and apply patches or compensating controls as needed.
- Potential unauthorized elevation of privileges within authentik deployments
- Risk of unintended role assignments or superuser status grants
- Need for verification of current authentik version and configurations
- Potential impact on access control and identity management
Technical summary
The vulnerability in authentik allows an account with delegated permissions to manage groups, group membership, or users to grant superuser status or assign existing roles without the required permissions. This issue arises from inconsistent group hierarchy checks for superuser status inherited from ancestor groups and a lack of authorization checks in role assignment to groups. The vulnerability is addressed in authentik versions 2026.2.7, 2026.5.7, and 2026.8.2.
Defensive priority
Defenders should prioritize verifying exposure in their authentik deployments, especially where delegated management capabilities are in use, and apply patches or compensating controls as needed.
Recommended defensive actions
- Verify authentik deployment versions and configurations to identify potential exposure
- Assess delegated management capabilities and permissions in use
- Apply patches to versions 2026.2.7, 2026.5.7, or 2026.8.2 as applicable
- Review and adjust role assignments and group memberships
- Monitor for suspicious activity related to authentik deployments
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and fixed versions. Official advisories and code changes are available from the authentik GitHub repository. The vulnerability allows an account with delegated permissions to manage groups, group membership, or users to grant superuser status or assign existing roles without required permissions, affecting deployments with delegated management capabilities. Defenders should verify exposure, especially in such deployments, and apply patches or compensating
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94609 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94609
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94609 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94609
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.goauthentik.io/releases/2026.2
-
Source reference
Unverified legacy reference
URL: https://docs.goauthentik.io/releases/2026.5
-
Source reference
Unverified legacy reference
URL: https://docs.goauthentik.io/releases/2026.8
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/commit/5f95b86f6f70c3bd8c625a4f9ae474e235f84030
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/commit/67317f66f1b7eb16f2a26bf550dfd73699d49d87
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/commit/67e470dde8c81a40ee27ec6e178462368c561a60
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/commit/898e4e4fa070642a3541a376af0de64fe3ffeb67
-
Source reference
Unverified legacy reference
URL: https://github.com/goauthentik/authentik/pull/25956
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.