PT-2026-7893 · Traefik+2 · Traefik+2

Imlonghao

·

Publicado

2026-02-12

·

Atualizado

2026-04-16

·

CVE-2026-25748

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2025.10.4 authentik versions prior to 2025.12.4
Description authentik is an open-source identity provider. A malformed cookie could bypass authentication when using forward authentication with the authentik Proxy Provider in conjunction with Traefik or Caddy as a reverse proxy. The absence of authentik-specific X-Authentik-* headers with a malicious cookie could grant access to an attacker, depending on the application.
Recommendations Update to authentik version 2025.10.4 or later. Update to authentik version 2025.12.4 or later.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-AUTHENTIK-2026-25748
CVE-2026-25748
GHSA-FJ56-5763-J8PP

Produtos afetados

Caddy
Traefik
Authentik