PT-2026-56530 · Authentik · Authentik
CVE-2026-54730
·
Published
2026-07-08
·
Updated
2026-08-24
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2026.2.6
authentik versions prior to 2026.5.5
Description
In enterprise deployments using a Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage, the authentication flow advances without confirming that the out-of-band device attestation was completed. The device attestation process occurs within a verification iframe that interacts with the Google Verified Access API. However, the system treats the flow as successful immediately upon submission of the stage. This allows an attacker to bypass the verification iframe and authenticate using an unverified device. If device trust is the sole additional authentication factor, this protection is completely bypassed, although other active factors remain effective.
Recommendations
Update to version 2026.2.6.
Update to version 2026.5.5.
As a temporary mitigation, avoid using the Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage in authentication flows.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Authentik