PT-2026-7894 · Authentik · Authentik

·

CVE-2026-25922

·

Publicado

2026-02-12

·

Atualizado

2026-04-16

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2025.8.6 authentik versions prior to 2025.10.4 authentik versions prior to 2025.12.4
Description authentik is an open-source identity provider. When using a SAML Source with the 'Verify Assertion Signature' option enabled under 'Verification Certificate' and 'Verify Response Signature' disabled, or without a configured 'Encryption Certificate' under 'Advanced Protocol settings', an attacker could inject a malicious assertion before the signed assertion that authentik would use. This could allow for unauthorized access or manipulation of data.
Recommendations Update authentik to version 2025.8.6. Update authentik to version 2025.10.4. Update authentik to version 2025.12.4.

Exploit

Correção

Improper Verification of Cryptographic Signature

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-AUTHENTIK-2026-25922
CVE-2026-25922
GHSA-JH35-C4CC-WJM4

Produtos afetados

Authentik