PT-2022-27786 · Authentik · Authentik
Dreamingraven
·
Published
2022-12-28
·
Updated
2026-04-16
·
CVE-2022-46172
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2022.10.4
authentik versions prior to 2022.11.4
Description
The issue allows any authenticated user to create an arbitrary number of accounts through the default flows, which can circumvent policies where it is undesirable for users to create new accounts by themselves. This may affect other applications as the new basic accounts would exist throughout the SSO infrastructure. By default, the newly created accounts cannot be logged into as no password reset exists by default, but password resets are likely to be enabled by most installations. The issue pertains to the user context used in the default-user-settings-flow, /api/v3/flows/instances/default-user-settings-flow/execute/.
Recommendations
For versions prior to 2022.10.4, update to version 2022.10.4 or later.
For versions prior to 2022.11.4, update to version 2022.11.4 or later.
Exploit
Fix
Improper Privilege Management
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Authentik