PT-2025-27232 · Authentik · Authentik

Beryju

·

Published

2025-06-27

·

Updated

2026-04-16

·

CVE-2025-52553

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: authentik versions prior to 2025.4.3 authentik versions prior to 2025.6.3
Description: The issue arises from the way authentik handles tokens after authorizing access to a RAC endpoint. A token is created for a single connection and sent to the client in the URL, but the check to ensure this token is only valid for the session of the user who authorized the connection is missing in affected versions. This could allow a malicious user to access the same session by copying the URL, for example, during a screenshare.
Recommendations: For versions prior to 2025.4.3 and 2025.6.3, as a temporary workaround, consider decreasing the duration a token is valid for by setting Connection expiry to minutes=5 in the RAC Provider settings. Enable the option Delete authorization on disconnect to minimize the risk of exploitation. Update to version 2025.4.3 or 2025.6.3 to resolve the issue.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2025-52553
CVE-2025-52553
GHSA-WR3V-9P2C-CHX7

Affected Products

Authentik