PT-2022-27786 · Authentik · Authentik

Dreamingraven

·

Published

2022-12-28

·

Updated

2026-04-16

·

CVE-2022-46172

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2022.10.4 authentik versions prior to 2022.11.4
Description The issue allows any authenticated user to create an arbitrary number of accounts through the default flows, which can circumvent policies where it is undesirable for users to create new accounts by themselves. This may affect other applications as the new basic accounts would exist throughout the SSO infrastructure. By default, the newly created accounts cannot be logged into as no password reset exists by default, but password resets are likely to be enabled by most installations. The issue pertains to the user context used in the default-user-settings-flow, /api/v3/flows/instances/default-user-settings-flow/execute/.
Recommendations For versions prior to 2022.10.4, update to version 2022.10.4 or later. For versions prior to 2022.11.4, update to version 2022.11.4 or later.

Exploit

Fix

Improper Privilege Management

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2022-46172
CVE-2022-46172
GHSA-HV8R-6W7P-MPC5

Affected Products

Authentik