PT-2025-47494 · Authentik · Authentik
Published
2025-11-19
·
Updated
2026-04-16
·
CVE-2025-64521
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2025.8.5
authentik versions prior to 2025.10.2
Description
authentik is an open-source Identity Provider. Before versions 2025.8.5 and 2025.10.2, when authenticating with
client id and client secret to an OAuth provider, authentik created a service account for the provider. Authentication for this account was possible even when the account was deactivated. Other permissions were correctly applied, and federation with other providers still respected assigned policies.Recommendations
Update to authentik version 2025.8.5 or later.
Update to authentik version 2025.10.2 or later.
As a workaround, add a policy to the application that explicitly checks if the service account is still valid and denies access if it is not.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Authentik