PT-2026-56530 · Authentik · Authentik

CVE-2026-54730

·

Published

2026-07-08

·

Updated

2026-08-24

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2026.2.6 authentik versions prior to 2026.5.5
Description In enterprise deployments using a Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage, the authentication flow advances without confirming that the out-of-band device attestation was completed. The device attestation process occurs within a verification iframe that interacts with the Google Verified Access API. However, the system treats the flow as successful immediately upon submission of the stage. This allows an attacker to bypass the verification iframe and authenticate using an unverified device. If device trust is the sole additional authentication factor, this protection is completely bypassed, although other active factors remain effective.
Recommendations Update to version 2026.2.6. Update to version 2026.5.5. As a temporary mitigation, avoid using the Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage in authentication flows.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2026-54730
CVE-2026-54730
GHSA-3V9H-3HRM-29CX

Affected Products

Authentik