Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Android-Login-Analysis

#37539of 55,077
7.5Total CVSS
Vulnerabilities · 1
PT-2026-45833
7.5
2026-06-02
Authentik · Authentik · CVE-2026-41577
**Name of the Vulnerable Software and Affected Versions** authentik versions prior to 2025.12.5 authentik versions prior to 2026.2.3 **Description** The SAML source response processor `ResponseProcessor.parse()` fails to validate the Conditions element on assertions. Specifically, `NotBefore`, `NotOnOrAfter`, and `AudienceRestriction` are ignored, which enables the replay of expired assertions and the acceptance of assertions intended for different service providers. **Recommendations** Update to version 2025.12.5. Update to version 2026.2.3.