Known Vulnerabilities for Authentik by Goauthentik
Listed below are 10 of the newest known vulnerabilities associated with "Authentik" by "Goauthentik".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72537 json | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72534 json | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-61574 json | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list return... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-59243 json | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker abl... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-57580 json | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-55106 json | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API doe... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-54730 json | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stag... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-49448 json | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be b... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-49443 json | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the abil... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-47201 json | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source A... | Not Provided | 2026-06-02 | 2026-06-03 |