PT-2026-98033 · Authentik · Authentik
CVE-2026-94609
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2026.2.7
authentik versions prior to 2026.5.7
authentik versions prior to 2026.8.2
Description
An account with delegated permissions to manage a user, group, or group membership can grant superuser status to an account or assign an existing role to a group without possessing the necessary permissions. This occurs because group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. This issue only affects deployments that delegate these management capabilities to accounts that are not full administrators.
Recommendations
Update to version 2026.2.7.
Update to version 2026.5.7.
Update to version 2026.8.2.
Exploit
Fix
Improper Privilege Management
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Authentik