PT-2026-7894 · Authentik · Authentik

Odgrso

·

Published

2026-02-12

·

Updated

2026-04-16

·

CVE-2026-25922

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2025.8.6 authentik versions prior to 2025.10.4 authentik versions prior to 2025.12.4
Description authentik is an open-source identity provider. When using a SAML Source with the 'Verify Assertion Signature' option enabled under 'Verification Certificate' and 'Verify Response Signature' disabled, or without a configured 'Encryption Certificate' under 'Advanced Protocol settings', an attacker could inject a malicious assertion before the signed assertion that authentik would use. This could allow for unauthorized access or manipulation of data.
Recommendations Update authentik to version 2025.8.6. Update authentik to version 2025.10.4. Update authentik to version 2025.12.4.

Exploit

Fix

Improper Verification of Cryptographic Signature

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2026-25922
CVE-2026-25922
GHSA-JH35-C4CC-WJM4

Affected Products

Authentik