📦 Authentik

by Goauthentik

🔍 What is Authentik?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25227

CRITICAL CVSS 9.1 Feb 12, 2026

This vulnerability in authentik allows authenticated users with specific delegated permissions to execute arbitrary code on the authentik server container via the test endpoint. It affects authentik d...

CVE-2025-52553

CRITICAL CVSS 9.6 Jun 27, 2025

This vulnerability in authentik allows session hijacking through Remote Access Control (RAC) tokens. An attacker who obtains a RAC token URL (e.g., via screenshare) can use it to access the same sessi...

CVE-2024-52289

CRITICAL CVSS 9.8 Nov 21, 2024

This vulnerability allows attackers to bypass OAuth2 redirect URI validation in authentik by exploiting improper regex escaping. Attackers can register malicious domains that match the regex pattern o...

CVE-2024-47070

CRITICAL CVSS 9.0 Sep 27, 2024

This vulnerability allows attackers to bypass password authentication in authentik by sending a malformed X-Forwarded-For header containing a non-IP address value like 'a'. This enables logging into a...

CVE-2023-26481

CRITICAL CVSS 9.1 Mar 4, 2023

This vulnerability in authentik allows attackers to reset passwords for any user account when administrators create recovery links or send recovery URLs. Attackers can exploit insufficient token valid...

CVE-2026-25922

HIGH CVSS 8.8 Feb 12, 2026

This vulnerability in authentik allows attackers to bypass SAML authentication by injecting malicious assertions before legitimate signed ones. It affects authentik instances with specific SAML Source...

CVE-2025-53942

HIGH CVSS 7.4 Jul 23, 2025

This vulnerability allows deactivated users who registered via OAuth/SAML to retain partial system access in authentik. They can authorize applications if they know the application URL, despite being ...

CVE-2025-29928

HIGH CVSS 8.0 Mar 28, 2025

authentik versions prior to 2024.12.4 and 2025.2.3 have a session management vulnerability when configured with database session storage. Attackers with existing sessions could maintain access even af...

CVE-2024-52287

HIGH CVSS 7.2 Nov 21, 2024

This vulnerability in authentik allows attackers to obtain OAuth tokens with unauthorized scopes when using client_credentials or device_code grants. Attackers can gain access to resources beyond thei...

CVE-2024-42490

HIGH CVSS 7.5 Aug 22, 2024

This vulnerability in authentik allows unauthenticated users to access sensitive API endpoints if they know specific object UUIDs. It affects authentik Identity Provider deployments, potentially expos...

CVE-2024-37905

HIGH CVSS 8.8 Jun 28, 2024

This vulnerability in authentik's API-Access-Token mechanism allows attackers to escalate privileges to full admin access. Any authentik instance running vulnerable versions is affected, enabling atta...

CVE-2024-21637

HIGH CVSS 7.6 Jan 11, 2024

Authentik is vulnerable to reflected Cross-Site Scripting (XSS) via JavaScript-URIs in OpenID Connect flows when using response_mode=form_post. This allows attackers to execute arbitrary JavaScript in...

CVE-2023-48228

HIGH CVSS 7.5 Nov 21, 2023

This vulnerability allows attackers to bypass PKCE (Proof Key for Code Exchange) protection in authentik's OAuth2 flows. When an OAuth2 flow is initiated with a code_challenge but the attacker omits t...

CVE-2023-36456

HIGH CVSS 8.3 Jul 6, 2023

This vulnerability in authentik allows attackers to spoof IP addresses by manipulating X-Forwarded-For and X-Real-IP headers. It affects authentik deployments without reverse proxies, enabling IP bypa...

CVE-2025-64521

MEDIUM CVSS 4.8 Nov 19, 2025

This vulnerability allows deactivated service accounts in authentik to still authenticate via OAuth client credentials, bypassing account status controls. It affects authentik deployments using OAuth ...

CVE-2025-64708

MEDIUM CVSS 5.8 Nov 19, 2025

This vulnerability in authentik allows expired invitations to remain valid for up to 5 minutes or longer during system backlog, potentially enabling unauthorized access. It affects all authentik deplo...