Authentik API-Access-Token Vulnerability Allows for Admin User Privileges Exploit
CVE-2024-37905
8.8HIGH
What is CVE-2024-37905?
The Authentik Identity Provider, an open-source solution for identity management, has a critical vulnerability within its API-Access-Token mechanism. This vulnerability can be exploited by malicious actors to gain unauthorized admin access, allowing them to manipulate user accounts, reset passwords, and potentially disrupt service integrity. Users and administrators are advised to update to patched versions 2024.2.4, 2024.4.2, or 2024.6.0 to mitigate this unauthorized access risk.
Affected Version(s)
authentik < 2024.6.0 < 2024.6.0
authentik < 2024.4.2 < 2024.4.2
authentik < 2024.2.4 < 2024.2.4