Known Vulnerabilities for Authentik by Authentik Security
Listed below are 10 of the newest known vulnerabilities associated with "Authentik" by "Authentik Security".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72537 json | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72534 json | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-59243 json | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker abl... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-49448 json | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be b... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-49443 json | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the abil... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-47201 json | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source A... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-44649 json | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, i... | Not Provided | 2026-05-29 | 2026-06-02 |
| CVE-2026-42849 json | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages ... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-41577 json | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-41569 json | authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-suppl... | Not Provided | 2026-06-02 | 2026-06-03 |