VendorsGoauthentikauthentikall versions
Vulnerabilities

Goauthentik Authentik

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2023-48228
OAuth2: PKCE can be fully circumvented
Published 2023-11-21 · Modified
9.8EPSS 0.012
CVE-2022-46145
authentik vulnerable to unauthorized user creation and potential account takeover
Published 2022-12-02 · Modified
9.8EPSS 0.012
CVE-2024-52289
authentik has an insecure default configuration for OAuth2 Redirect URIs
Published 2024-11-21 · Modified
9.8EPSS 0.011
CVE-2023-46249
authentik potential installation takeover when default admin user is deleted
Published 2023-10-31 · Modified
9.8EPSS 0.007
CVE-2024-38371
Insufficient access control for OAuth2 Device Code flow in authentik
Published 2024-06-28 · Analyzed
9.8EPSS 0.006
CVE-2026-49448
authentik: SourceStage bypass via empty POST
Published 2026-06-02 · Analyzed
9.8EPSS 0.006
CVE-2025-52553
authentik has Insufficient Session verification for Remote Access Control endpoint access
Published 2025-06-27 · Analyzed
9.6EPSS 0.005
CVE-2022-23555
authentik vulnerable to Improper Authentication via invitation URL token reuse
Published 2022-12-28 · Modified
9.4EPSS 0.009
CVE-2026-42849
authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover
Published 2026-06-02 · Analyzed
9.3EPSS 0.005
CVE-2026-25227
authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint
Published 2026-02-12 · Analyzed
9.1EPSS 0.008
CVE-2023-26481
Insufficient user check in FlowTokens by Email stage
Published 2023-03-04 · Modified
9.1EPSS 0.003
CVE-2024-47070
authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP header
Published 2024-09-27 · Analyzed
9.0EPSS 0.006
CVE-2024-37905
Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik
Published 2024-06-28 · Analyzed
8.8EPSS 0.008
CVE-2024-23647
PKCE downgrade attack in Authentik
Published 2024-01-30 · Modified
8.8EPSS 0.005
CVE-2026-49443
authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API
Published 2026-06-02 · Analyzed
8.8EPSS 0.004
CVE-2026-25922
authentik has a Signature Verification Bypass via SAML Assertion Wrapping
Published 2026-02-12 · Analyzed
8.8EPSS 0.003
CVE-2026-25748
authentik has a forward authentication bypass with broken cookie
Published 2026-02-12 · Analyzed
8.6EPSS 0.008
CVE-2026-47201
authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
Published 2026-06-02 · Analyzed
8.5EPSS 0.003
CVE-2023-36456
Authentik lacks Proxy IP headers validation
Published 2023-07-06 · Modified
8.3EPSS 0.008
CVE-2025-29928
authentik's deletion of sessions did not revoke sessions when using database session storage
Published 2025-03-28 · Analyzed
8.0EPSS 0.004
CVE-2024-21637
XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Mode
Published 2024-01-11 · Modified
7.6EPSS 0.005
CVE-2024-42490
authentik has Insufficient Authorization for several API endpoints
Published 2024-08-22 · Analyzed
7.5EPSS 0.005
CVE-2026-41577
authentik: SAML source does not validate Conditions, timing, or audience on assertions
Published 2026-06-02 · Analyzed
7.5EPSS 0.002
CVE-2025-53942
authentik has an insufficient check for account active status during OAuth/SAML authentication
Published 2025-07-23 · Analyzed
7.4EPSS 0.005
CVE-2024-52287
authentik performs insufficient validation of OAuth scopes
Published 2024-11-21 · Analyzed
7.2EPSS 0.006
CVE-2026-41569
authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints
Published 2026-06-02 · Analyzed
6.9EPSS 0.003
CVE-2024-47077
authentik cross-provider token validation problems
Published 2024-09-27 · Analyzed
6.5EPSS 0.004
CVE-2022-46172
authentik allows existing authenticated users to create arbitrary accounts
Published 2022-12-28 · Modified
6.4EPSS 0.005
CVE-2024-52307
authentik allows a timing attack due to missing constant time comparison for metrics view
Published 2024-11-21 · Analyzed
6.3EPSS 0.006
CVE-2025-64708
authentik invitation expiry is delayed by at least 5 minutes
Published 2025-11-19 · Analyzed
5.8EPSS 0.002
CVE-2023-39522
Username enumeration attack in goauthentik
Published 2023-08-29 · Modified
5.3EPSS 0.006
CVE-2024-11623
Stored XSS in authentik
Published 2025-02-04 · Analyzed
4.8EPSS 0.003
CVE-2025-64521
authentik deactivated service accounts can authenticate to OAuth
Published 2025-11-19 · Analyzed
4.8EPSS 0.002