XML Signature Wrapping Vulnerability in Authentik Open-Source Identity Provider
CVE-2026-47201

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
2 June 2026

What is CVE-2026-47201?

Authentik, an open-source identity provider, has a vulnerability in its SAML Source ACS endpoint affecting versions before 2025.12.5, 2026.2.3, and 2026.5.1. This flaw allows an attacker, with any account at the upstream Identity Provider (IdP), to exploit XML Signature Wrapping when validating SAML responses. Consequently, they can reuse a valid signed assertion to authenticate themselves as a different federated user, potentially compromising user accounts and access controls. The issue is addressed in the patched versions.

Affected Version(s)

authentik < 2025.12.5 < 2025.12.5

authentik < 2026.2.3 < 2026.2.3

authentik < 2026.5.1 < 2026.5.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.