PT-2026-98033 · Authentik · Authentik

CVE-2026-94609

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2026.2.7 authentik versions prior to 2026.5.7 authentik versions prior to 2026.8.2
Description An account with delegated permissions to manage a user, group, or group membership can grant superuser status to an account or assign an existing role to a group without possessing the necessary permissions. This occurs because group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. This issue only affects deployments that delegate these management capabilities to accounts that are not full administrators.
Recommendations Update to version 2026.2.7. Update to version 2026.5.7. Update to version 2026.8.2.

Exploit

Fix

Improper Privilege Management

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94609
GHSA-H6C5-MPVQ-J4JC

Affected Products

Authentik