PT-2026-45854 · Authentik · Authentik
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2026.2.3
Description
The WS-Federation provider in this open-source identity provider validates the user-supplied
wreply parameter using a raw string prefix check instead of proper URL parsing. An attacker can craft a login link with a wreply value from a different origin that bypasses this check, leading the victim's browser to POST the signed WS-Federation login response to infrastructure controlled by the attacker.Recommendations
Update to version 2026.2.3.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Authentik