SAML Assertion Vulnerability in authentik Identity Provider
CVE-2026-25922

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
12 February 2026

What is CVE-2026-25922?

The authentik identity provider, before versions 2025.8.6, 2025.10.4, and 2025.12.4, is susceptible to a vulnerability due to improper configuration. When utilizing a SAML Source with the Verify Assertion Signature option enabled but not the Verify Response Signature, or without the Encryption Certificate set up, an attacker could inject a malicious assertion preceding the signed assertion utilized by authentik. This flaw emphasizes the importance of correct protocol settings in safeguarding against unauthorized access and data breaches.

Affected Version(s)

authentik < 2025.8.6 < 2025.8.6

authentik >= 2025.10.0-rc1, < 2025.10.4 < 2025.10.0-rc1, 2025.10.4

authentik >= 2025.10.0-rc1, < 2025.12.4 < 2025.10.0-rc1, 2025.12.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.