authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage
Summary
| CVE | CVE-2026-94606 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-24 17:17:17 UTC |
| Updated | 2026-09-24 17:17:17 UTC |
| Description | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a target user's password can substitute an attacker-controlled address, receive the one-time code, and finish enrolling the factor as the target. The target must not have enrolled the email factor already. Successful enrollment gives the actor a session as the target and access to single sign-on applications behind the account. Other authenticator types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2. |
Risk And Classification
Primary CVSS: v3.1 8.9 HIGH from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Problem Types: CWE-287 | CWE-807 | CWE-287 CWE-287: Improper Authentication | CWE-807 CWE-807: Reliance on Untrusted Inputs in a Security Decision
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.9 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
| 3.1 | CNA | DECLARED | 8.9 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
LowCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Goauthentik | Authentik | affected < 2026.2.7 | Not specified |
| CNA | Goauthentik | Authentik | affected >= 2026.5.0, < 2026.5.7 | Not specified |
| CNA | Goauthentik | Authentik | affected >= 2026.8.0, < 2026.8.2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/goauthentik/authentik/commit/1fcf9868133e5d05e266edbc1f6f3ee9... | [email protected] | github.com | |
| github.com/goauthentik/authentik/commit/01d4349f2aaa9beda532f92e2a251a17... | [email protected] | github.com | |
| github.com/goauthentik/authentik/commit/c10ae83ebf8c61de2f1922edf1fab504... | [email protected] | github.com | |
| docs.goauthentik.io/releases/2026.5 | [email protected] | docs.goauthentik.io | |
| docs.goauthentik.io/releases/2026.2 | [email protected] | docs.goauthentik.io | |
| github.com/goauthentik/authentik/pull/25973 | [email protected] | github.com | |
| github.com/goauthentik/authentik/pull/25963 | [email protected] | github.com | |
| github.com/goauthentik/authentik/commit/ec41732339726fba477182c0906a8d93... | [email protected] | github.com | |
| github.com/goauthentik/authentik/security/advisories/GHSA-qgqp-xh8r-v73r | [email protected] | github.com | |
| docs.goauthentik.io/releases/2026.8 | [email protected] | docs.goauthentik.io | |
| github.com/goauthentik/authentik/releases/tag/version/2026.2.7 | [email protected] | github.com | |
| github.com/goauthentik/authentik/pull/25958 | [email protected] | github.com | |
| github.com/goauthentik/authentik/releases/tag/version/2026.8.2 | [email protected] | github.com | |
| github.com/goauthentik/authentik/releases/tag/version/2026.5.7 | [email protected] | github.com | |
| github.com/goauthentik/authentik/pull/25968 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.