PT-2025-47495 · Authentik · Authentik

Published

2025-11-19

·

Updated

2026-04-16

·

CVE-2025-64708

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2025.8.5 authentik versions prior to 2025.10.2
Description authentik, an open-source Identity Provider, had a flaw where invitations remained valid even after expiration. This relied on background tasks to remove expired invitations, with a potential delay of up to 5 minutes, or longer with a large backlog of tasks. The issue stemmed from not validating invitation validity during the invitation process. A workaround involved creating a policy to explicitly check invitation validity and denying access if expired.
Recommendations Update to authentik version 2025.8.5 or later. Update to authentik version 2025.10.2 or later. Implement a policy that explicitly checks whether the invitation is still valid and denies access if the invitation is not valid.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2025-64708
CVE-2025-64708
GHSA-CH7Q-53V8-73PC
GO-2025-4136
SUSE-SU-2026:0037-1

Affected Products

Authentik