PatchSiren

goauthentik CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH goauthentik CVE published 2026-09-24

CVE-2026-94613

An authentik deployment using SAML in either the identity-provider or SAML source role is vulnerable to a denial-of-service attack by an unauthenticated attacker. The attacker can submit a malformed SAML message that stops the worker handling /application/saml/* or /source/saml/*, causing requests assigned to that worker to fail. Worker process termination and automatic restart do not destroy database-bac [truncated]

HIGH goauthentik CVE published 2026-09-24

CVE-2026-94609

CVE-2026-94609 is a high-severity vulnerability in authentik, an open-source identity provider. The issue allows an account with delegated permission to manage a group, group membership, or a user to grant superuser status or assign an existing role without holding the required permissions. This affects deployments that delegate these capabilities to non-full administrators. The vulnerability is fixed in [truncated]

HIGH goauthentik CVE published 2026-09-24

CVE-2026-94606

CVE-2026-94606 is a high-severity vulnerability in authentik, an open-source identity provider. The issue allows an attacker who knows a target user's password to enroll an email authenticator factor on behalf of the target, potentially leading to unauthorized access to single sign-on applications. This vulnerability is fixed in authentik versions 2026.2.7, 2026.5.7, and 2026.8.2.

HIGH goauthentik CVE published 2026-08-18

CVE-2026-61574

CVE-2026-61574 authentik Remote Access Control endpoint listing vulnerability allows any authenticated user to read every endpoint along with its host and stored credentials, and open a connection to an endpoint belonging to another application, exposing stored credentials for managed RDP, SSH, and VNC targets and granting interactive access to systems the user was never authorized to reach. This issue re [truncated]

CRITICAL goauthentik CVE published 2026-08-18

CVE-2026-57580

CVE-2026-57580 is a critical vulnerability in authentik, an open-source identity provider. The issue allows an attacker with an account on the source identity provider to inject an XML comment in a NameID, potentially leading to account takeover without the victim's password or the identity provider's private key. This vulnerability affects inbound SAML Source configurations using non-default USERNAME_LIN [truncated]

MEDIUM goauthentik CVE published 2026-08-18

CVE-2026-55106

CVE-2026-55106 debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T17:16:59.500Z. This medium-severity vulnerability in authentik's LDAP Source API diagnostic action could potentially expose directory structure and account information. Defenders managing authentik instances with LDAP Source configurations should assess exposure and prioritize upgrading to fixed versions [truncated]

HIGH goauthentik CVE published 2026-08-18

CVE-2026-54730

CVE-2026-54730 is a high-severity vulnerability in authentik, an open-source identity provider. The vulnerability allows an attacker to bypass device trust verification, potentially leading to unauthorized access. The issue is fixed in versions 2026.2.6 and 2026.5.5. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device [truncated]

HIGH goauthentik CVE published 2026-05-22

CVE-2026-40172

The CVE record for CVE-2026-40172 was published on 2026-05-22T19:17:03.893Z and has not been modified since then. The NVD entry is currently Deferred. This high-severity vulnerability in Authentik open-source identity provider versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2 allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups w [truncated]

HIGH goauthentik CVE published 2026-05-22

CVE-2026-40166

CVE-2026-40166 is a vulnerability in the authentik open-source identity provider. Authentik versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2 contain a flaw that allows authenticated non-admin users with at least one OAuth2 access token to retrieve the client_secret of confidential OAuth2 providers they have previously authenticated against. This issue exposes sensitive information to users wi [truncated]

HIGH goauthentik CVE published 2026-05-21

CVE-2026-40165

CVE-2026-40165 is a high-severity authentication bypass in authentik’s SAML login flow. According to the CVE description, an attacker who already has an account on a SAML Source and can influence their NameID value may be able to inject an XML comment into the NameID field, causing authentik to read only part of the value and potentially map the login to another user’s account. The issue is fixed in authe [truncated]