PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94609 goauthentik CVE debrief

CVE-2026-94609 is a high-severity vulnerability in authentik, an open-source identity provider. The issue allows an account with delegated permission to manage a group, group membership, or a user to grant superuser status or assign an existing role without holding the required permissions. This affects deployments that delegate these capabilities to non-full administrators. The vulnerability is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.

Vendor
goauthentik
Product
authentik
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-25
Advisory published
2026-09-24
Advisory updated
2026-09-25

Who should care

Defenders responsible for authentik deployments, especially those with delegated management capabilities, should assess their exposure and take necessary actions to mitigate the vulnerability.

Why it matters

CVE-2026-94609 is a high-severity vulnerability in authentik that allows unauthorized privilege escalation and role assignment. Defenders should verify exposure, especially in deployments with delegated management capabilities, and apply patches or compensating controls as needed.

  • Potential unauthorized elevation of privileges within authentik deployments
  • Risk of unintended role assignments or superuser status grants
  • Need for verification of current authentik version and configurations
  • Potential impact on access control and identity management

Technical summary

The vulnerability in authentik allows an account with delegated permissions to manage groups, group membership, or users to grant superuser status or assign existing roles without the required permissions. This issue arises from inconsistent group hierarchy checks for superuser status inherited from ancestor groups and a lack of authorization checks in role assignment to groups. The vulnerability is addressed in authentik versions 2026.2.7, 2026.5.7, and 2026.8.2.

Defensive priority

Defenders should prioritize verifying exposure in their authentik deployments, especially where delegated management capabilities are in use, and apply patches or compensating controls as needed.

Recommended defensive actions

  • Verify authentik deployment versions and configurations to identify potential exposure
  • Assess delegated management capabilities and permissions in use
  • Apply patches to versions 2026.2.7, 2026.5.7, or 2026.8.2 as applicable
  • Review and adjust role assignments and group memberships
  • Monitor for suspicious activity related to authentik deployments

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and fixed versions. Official advisories and code changes are available from the authentik GitHub repository. The vulnerability allows an account with delegated permissions to manage groups, group membership, or users to grant superuser status or assign existing roles without required permissions, affecting deployments with delegated management capabilities. Defenders should verify exposure, especially in such deployments, and apply patches or compensating

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94609 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94609

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94609 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94609

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.