PT-2026-7893 · Traefik+2 · Traefik+2
Imlonghao
·
Published
2026-02-12
·
Updated
2026-04-16
·
CVE-2026-25748
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2025.10.4
authentik versions prior to 2025.12.4
Description
authentik is an open-source identity provider. A malformed cookie could bypass authentication when using forward authentication with the authentik Proxy Provider in conjunction with Traefik or Caddy as a reverse proxy. The absence of authentik-specific X-Authentik-* headers with a malicious cookie could grant access to an attacker, depending on the application.
Recommendations
Update to authentik version 2025.10.4 or later.
Update to authentik version 2025.12.4 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Caddy
Traefik
Authentik