PT-2026-56531 · Authentik · Authentik
CVE-2026-55106
·
Published
2026-07-08
·
Updated
2026-08-24
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2026.2.6
authentik versions prior to 2026.5.5
Description
A diagnostic action on the LDAP Source API fails to enforce the object-level read-authorization filter applied to the rest of the API. This allows any party with API access, including unauthenticated clients, to trigger the diagnostic action against a configured LDAP Source. The server uses the source's bind credentials to connect to the upstream directory and returns a limited set of directory entries. This exposure reveals distinguished names, attribute names, directory structure, naming conventions, and the existence of specific accounts and groups, although attribute values remain hidden. Deployments without a configured LDAP Source are not affected.
Recommendations
Update to version 2026.2.6.
Update to version 2026.5.5.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Authentik