<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Authentik (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/authentik.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/authentik-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Authentik (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-49448 – authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49448</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-49448</strong></p>
  <p>authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49443 – authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49443</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49443</strong></p>
  <p>authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47201 – authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47201</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47201</strong></p>
  <p>authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue has been patched in versions 2025.12.5, 202…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42849 – authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42849</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42849</strong></p>
  <p>authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44649 – SillyTavern is a locally installed user interface that allows users to interact ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44649</guid>
    <pubDate>Fri, 29 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44649</strong></p>
  <p>SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to automatically log in users when SSO is configured. There is no validation that these headers originate…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40172 – authentik is an open-source identity provider. In versions prior to 2025.12.5 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40172</guid>
    <pubDate>Fri, 22 May 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40172</strong></p>
  <p>authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring enable_group_superuser, leading to privilege escalation. This bypasses the stricter per…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40166 – authentik is an open-source identity provider. In versions prior to 2025.12.5 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40166</guid>
    <pubDate>Fri, 22 May 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40166</strong></p>
  <p>authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they have previously authenticated against, exposing sensitive information to users without the correct permissions. This logic is GET /api/v3/oauth2/acce…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40165 – authentik is an open-source identity provider. Versions 2025.12.4 and prior, and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40165</guid>
    <pubDate>Thu, 21 May 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40165</strong></p>
  <p>authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick authentik into only seeing a part of the NameID value, potentially allowing an atta…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25922 – authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25922</guid>
    <pubDate>Thu, 12 Feb 2026 20:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25922</strong></p>
  <p>authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificate setting under Advanced Protocol settings configured, it was possible for an attacker to inject a malicious assertion…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53942 – authentik is an open-source Identity Provider that emphasizes flexibility and ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53942</guid>
    <pubDate>Wed, 23 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53942</strong></p>
  <p>authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered through OAuth/SAML or linked their accounts to OAuth/SAML providers can still retain partial access to the system despite their accounts being deact…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52553 – authentik is an open-source identity provider. After authorizing access to a RAC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52553</guid>
    <pubDate>Fri, 27 Jun 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52553</strong></p>
  <p>authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session of the user who authorized the connection, however this check is missing in versions prior to 2025.6.3 and 2025.4.3. When, for example, using RAC duri…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29928 – authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29928</guid>
    <pubDate>Fri, 28 Mar 2025 15:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29928</strong></p>
  <p>authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would not revoke the session and the session holder would continue to have access to authentik. authentik 2025.2.3 and 2024.12.4 fix this issue. Switching…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-52289 – authentik is an open-source identity provider. Redirect URIs in the OAuth2 provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52289</guid>
    <pubDate>Thu, 21 Nov 2024 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-52289</strong></p>
  <p>authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value received as an allowed redirect URI, without escaping characters that have a special meaning in RegEx. Similarly, the documentation did not take this into…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-185</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52287 – authentik is an open-source identity provider. When using the client_credentials...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52287</guid>
    <pubDate>Thu, 21 Nov 2024 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52287</strong></p>
  <p>authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47070 – authentik is an open-source identity provider. A vulnerability that exists in ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47070</guid>
    <pubDate>Fri, 27 Sep 2024 16:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47070</strong></p>
  <p>authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any account with a known login or email address. The vulnerability requires the authentik instance to trust X-Forwarded-For heade…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42490 – authentik is an open-source Identity Provider. Several API endpoints can be acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42490</guid>
    <pubDate>Thu, 22 Aug 2024 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42490</strong></p>
  <p>authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/v3/crypto/certificatekeypairs/<uuid>/view_private_key/, and /api/v3/.../used_by/. Note that all of the affected API endpoints require the knowledge o…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38371 – authentik is an open-source Identity Provider. Access restrictions assigned to a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38371</guid>
    <pubDate>Fri, 28 Jun 2024 18:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38371</strong></p>
  <p>authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This issue has been patched in version(s) 2024.6.0, 2024.2.4 and 2024.4.3.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37905 – authentik is an open-source Identity Provider that emphasizes flexibility and ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37905</guid>
    <pubDate>Fri, 28 Jun 2024 18:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37905</strong></p>
  <p>authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been patched in version(s) 2024.2.4, 2024.4.2 and 2…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37905">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
