Object-Level Authorization Bypass in Open-Source Identity Provider by Authentik
CVE-2026-55106
5.3MEDIUM
What is CVE-2026-55106?
A vulnerability in Authentik's LDAP Source API allows unauthorized access to diagnostic actions. Prior to versions 2026.2.6 and 2026.5.5, an unauthenticated client could exploit this flaw to invoke diagnostic actions on the API. This could lead to exposure of directory structure details, revealing distinguished names and attribute names of entries, while not disclosing attribute values themselves. Deployments without a configured LDAP Source remain unaffected by this issue. The vulnerability has been addressed in newer software releases.
Affected Version(s)
authentik < 2026.2.6 < 2026.2.6
authentik >= 2026.5.0, < 2026.5.5 < 2026.5.0, 2026.5.5
