PT-2026-98034 · Authentik · Authentik
CVE-2026-94611
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2026.2.7
authentik versions prior to 2026.5.7
authentik versions prior to 2026.8.2
Description
API serializers return stored credentials when an account possesses view permission on specific configurations, regardless of whether the account is authorized to modify the configuration or access its secrets. This occurs in configurations related to one-time code delivery via mail or SMS, outbound provisioning targets, device trust integrations, identity sources, Kubernetes outpost integration, applications utilizing a client or shared secret, and applications using a proxy provider. The issue impacts deployments where view permissions are granted to accounts not intended to access these credentials.
Recommendations
Update to version 2026.2.7.
Update to version 2026.5.7.
Update to version 2026.8.2.
Exploit
Fix
Information Disclosure
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Authentik