Session Management Flaw in Authentik Identity Provider
CVE-2025-29928
What is CVE-2025-29928?
The Authentik identity provider has a significant issue affecting its session management functionalities. When configured to use the database for session storage, deleting sessions via the web interface or API does not effectively revoke the session. Consequently, session holders maintain unauthorized access, leading to potential unauthorized actions within the platform. Users are advised to switch to cache-based session storage as an interim measure until they can upgrade to versions 2024.12.4 or 2025.2.3, although this will necessitate session deletion and user re-authentication.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
authentik < 2024.12.4 < 2024.12.4
authentik < 2025.2.3 < 2025.2.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
