PT-2026-98036 · Authentik · Authentik

CVE-2026-94613

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2026.2.7 authentik versions prior to 2026.5.7 authentik versions prior to 2026.8.2
Description An unauthenticated attacker can submit a malformed SAML message to a deployment using SAML in the identity-provider or SAML source role. This action can terminate the worker process handling the '/application/saml/' or '/source/saml/' endpoints, causing requests assigned to that worker to fail. While worker process termination and automatic restarts do not destroy database-backed sessions, repeated malicious messages can lead to a sustained failure of legitimate traffic. SAML (Security Assertion Markup Language) is an open standard for exchanging authentication and authorization data between parties.
Recommendations Update to version 2026.2.7. Update to version 2026.5.7. Update to version 2026.8.2.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94613
GHSA-CXWX-9X59-28QM

Affected Products

Authentik