PT-2026-98035 · Authentik · Authentik
CVE-2026-94612
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2026.2.7
authentik versions prior to 2026.5.7
authentik versions prior to 2026.8.2
Description
An issue exists in the SAML Source where the system verifies the signature and validity period of an assertion but fails to confirm if the identity provider issued the assertion specifically for that Source or in response to a login request from it. Additionally, the SAML Source does not track previously accepted assertions, which enables replay attacks. An unauthenticated actor with a valid assertion can use one intended for a different service provider or reuse a previous assertion to authenticate as the user specified in the assertion.
Recommendations
Update to version 2026.2.7.
Update to version 2026.5.7.
Update to version 2026.8.2.
Exploit
Fix
Improper Authentication
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Authentik