PT-2025-47494 · Authentik · Authentik

Published

2025-11-19

·

Updated

2026-04-16

·

CVE-2025-64521

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2025.8.5 authentik versions prior to 2025.10.2
Description authentik is an open-source Identity Provider. Before versions 2025.8.5 and 2025.10.2, when authenticating with client id and client secret to an OAuth provider, authentik created a service account for the provider. Authentication for this account was possible even when the account was deactivated. Other permissions were correctly applied, and federation with other providers still respected assigned policies.
Recommendations Update to authentik version 2025.8.5 or later. Update to authentik version 2025.10.2 or later. As a workaround, add a policy to the application that explicitly checks if the service account is still valid and denies access if it is not.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2025-64521
CVE-2025-64521
GHSA-XR73-JQ5P-CH8R
GO-2025-4137
SUSE-SU-2026:0037-1

Affected Products

Authentik