PT-2026-56531 · Authentik · Authentik

CVE-2026-55106

·

Published

2026-07-08

·

Updated

2026-08-24

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2026.2.6 authentik versions prior to 2026.5.5
Description A diagnostic action on the LDAP Source API fails to enforce the object-level read-authorization filter applied to the rest of the API. This allows any party with API access, including unauthenticated clients, to trigger the diagnostic action against a configured LDAP Source. The server uses the source's bind credentials to connect to the upstream directory and returns a limited set of directory entries. This exposure reveals distinguished names, attribute names, directory structure, naming conventions, and the existence of specific accounts and groups, although attribute values remain hidden. Deployments without a configured LDAP Source are not affected.
Recommendations Update to version 2026.2.6. Update to version 2026.5.5.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2026-55106
CVE-2026-55106
GHSA-H8FF-C3H7-2GF8

Affected Products

Authentik