PT-2024-35153 · Authentik · Authentik

Matt1097

·

Published

2024-11-21

·

Updated

2026-04-16

·

CVE-2024-52287

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2024.8.5 authentik versions prior to 2024.10.3
Description The issue allows an attacker to obtain a token with scopes that haven't been configured in authentik when using the client credentials or device code OAuth grants.
Recommendations For versions prior to 2024.8.5, update to version 2024.8.5 or later. For versions prior to 2024.10.3, update to version 2024.10.3 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2024-52287
CVE-2024-52287
GHSA-V6M7-8J37-8F4V

Affected Products

Authentik