Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Authentik CRITICAL 9.8
CVE-2026-49448

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an em…

Fix: 2025.12.6 / 2026.2.4+
Fix from $2,300 2026-06-02
Authentik HIGH 8.8
CVE-2026-49443

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source c…

Fix: 2025.12.6 / 2026.2.4+
Fix from $1,950 2026-06-02
Authentik CRITICAL 9.3
CVE-2026-42849

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow …

Fix: 2025.12.5 / 2026.2.3+
Fix from $2,300 2026-06-02
Authentik HIGH 8.5
CVE-2026-47201

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerabl…

Fix: 2025.12.6 / 2026.2.4+
Fix from $1,950 2026-06-02
Authentik MEDIUM 6.1
CVE-2026-41569

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter usi…

Fix: 2026.2.3+
Fix from $1,600 2026-06-02
Authentik HIGH 7.5
CVE-2026-41577

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse(…

Fix: 2025.12.5 / 2026.2.3+
Fix from $1,950 2026-06-02
Authentik HIGH 8.8
CVE-2026-25922

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Asser…

Fix: 2025.8.6 / 2025.10.4+
Fix from $1,950 2026-02-12
Authentik HIGH 7.5
CVE-2026-25748

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication whe…

Fix: 2025.10.4 / 2025.12.4+
Fix from $1,950 2026-02-12
Authentik HIGH 7.2
CVE-2026-25227

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User t…

Fix: 2025.8.6 / 2025.10.4+
Fix from $1,950 2026-02-12
Authentik MEDIUM 5.3
CVE-2025-64708

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered …

Fix: 2025.8.5 / 2025.10.2+
Fix from $1,600 2025-11-19
Authentik HIGH 7.4
CVE-2025-53942

authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025…

Fix: 2025.4.4 / 2025.6.4+
Fix from $1,950 2025-07-23
Authentik CRITICAL 9.6
CVE-2025-52553

authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single conne…

Fix: 2025.4.3 / 2025.6.3+
Fix from $2,300 2025-06-27
Authentik HIGH 8.0
CVE-2025-29928

authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for sessio…

Fix: 2024.12.4 / 2025.2.3+
Fix from $1,950 2025-03-28
Authentik CRITICAL 9.8
CVE-2024-52289

authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect UR…

Fix: 2024.8.5 / 2024.10.3+
Fix from $2,300 2024-11-21
Authentik MEDIUM 5.6
CVE-2024-52307

authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to bru…

Fix: 2024.8.5 / 2024.10.3+
Fix from $1,600 2024-11-21
Authentik HIGH 7.2
CVE-2024-52287

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get …

Fix: 2024.8.5 / 2024.10.3+
Fix from $1,950 2024-11-21
Authentik MEDIUM 6.5
CVE-2024-47077

authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that…

Fix: 2024.6.5 / 2024.8.3+
Fix from $1,600 2024-09-27
Authentik CRITICAL 9.0
CVE-2024-47070

authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login…

Fix: 2024.6.5 / 2024.8.3+
Fix from $2,300 2024-09-27
Authentik HIGH 7.5
CVE-2024-42490

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main …

Fix: 2024.4.4 / 2024.6.4+
Fix from $1,950 2024-08-22
Authentik CRITICAL 9.8
CVE-2024-38371

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow…

Fix: 2024.2.4 / 2024.4.3+
Fix from $2,300 2024-06-28
Authentik HIGH 8.8
CVE-2024-37905

authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to g…

Fix: 2024.2.4 / 2024.4.3+
Fix from $1,950 2024-06-28
Authentik HIGH 8.8
CVE-2024-23647

Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that…

Fix: 2023.8.7 / 2023.10.7+
Fix from $1,950 2024-01-30
Authentik MEDIUM 5.4
CVE-2024-21637

Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in Ope…

Fix: 2023.8.6 / 2023.10.6+
Fix from $1,600 2024-01-11
Authentik CRITICAL 9.8
CVE-2023-48228

authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the …

Fix: 2023.8.5 / 2023.10.4+
Fix from $2,300 2023-11-21
Authentik CRITICAL 9.8
CVE-2023-46249

authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentia…

Fix: 2023.8.4 / 2023.10.2+
Fix from $2,300 2023-10-31
Authentik MEDIUM 5.3
CVE-2023-39522

goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to deter…

Fix: 2023.5.6 / 2023.6.2+
Fix from $1,600 2023-08-29
Authentik HIGH 7.3
CVE-2023-36456

authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For a…

Fix: 2023.4.3 / 2023.5.5+
Fix from $1,950 2023-07-06
Authentik MEDIUM 6.5
CVE-2023-26481

authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via ema…

Fix: 2022.12.3+
Fix from $1,600 2023-03-04
Authentik MEDIUM 6.4
CVE-2022-46172

authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticate…

Fix: 2022.10.4 / 2022.11.4+
Fix from $1,600 2022-12-28
Authentik HIGH 8.8
CVE-2022-23555

authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Imp…

Fix: 2022.10.4 / 2022.11.4+
Fix from $1,950 2022-12-28