PT-2026-98034 · Authentik · Authentik

CVE-2026-94611

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2026.2.7 authentik versions prior to 2026.5.7 authentik versions prior to 2026.8.2
Description API serializers return stored credentials when an account possesses view permission on specific configurations, regardless of whether the account is authorized to modify the configuration or access its secrets. This occurs in configurations related to one-time code delivery via mail or SMS, outbound provisioning targets, device trust integrations, identity sources, Kubernetes outpost integration, applications utilizing a client or shared secret, and applications using a proxy provider. The issue impacts deployments where view permissions are granted to accounts not intended to access these credentials.
Recommendations Update to version 2026.2.7. Update to version 2026.5.7. Update to version 2026.8.2.

Exploit

Fix

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94611
GHSA-M9H4-7J9C-55X9

Affected Products

Authentik