Authentication Bypass Vulnerability in authentik Identity Provider
CVE-2025-52553
What is CVE-2025-52553?
The authentik identity provider has a security flaw that allows unauthorized access to user sessions due to a missing validation check on session tokens. After accessing a RAC endpoint, a token is created and sent to the client via URL, which can be exploited by malicious users to hijack active sessions, particularly during activities like screensharing. To mitigate this issue, users should upgrade to authentik versions 2025.4.3 or 2025.6.3, configure shorter token expiry times, and enable the option to delete authorization on disconnect.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
authentik >= 2025.6.0-rc1, < 2025.6.3 < 2025.6.0-rc1, 2025.6.3
authentik < 2025.4.3 < 2025.4.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
