PatchSiren

Authentik Security CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Authentik Security CVE published 2026-08-11

CVE-2026-72537

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account, including superusers, by provisioning a SCIM user that matches an existing local user by username. This vulnerability impacts organizations using Authentik Security authentik through version 2026.5.6, particularly those with se [truncated]