PT-2026-7894 · Authentik · Authentik
Odgrso
·
Published
2026-02-12
·
Updated
2026-04-16
·
CVE-2026-25922
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2025.8.6
authentik versions prior to 2025.10.4
authentik versions prior to 2025.12.4
Description
authentik is an open-source identity provider. When using a SAML Source with the 'Verify Assertion Signature' option enabled under 'Verification Certificate' and 'Verify Response Signature' disabled, or without a configured 'Encryption Certificate' under 'Advanced Protocol settings', an attacker could inject a malicious assertion before the signed assertion that authentik would use. This could allow for unauthorized access or manipulation of data.
Recommendations
Update authentik to version 2025.8.6.
Update authentik to version 2025.10.4.
Update authentik to version 2025.12.4.
Exploit
Fix
Improper Verification of Cryptographic Signature
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Authentik