Object-Level Authorization Bypass in Open-Source Identity Provider by Authentik
CVE-2026-55106

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-55106?

A vulnerability in Authentik's LDAP Source API allows unauthorized access to diagnostic actions. Prior to versions 2026.2.6 and 2026.5.5, an unauthenticated client could exploit this flaw to invoke diagnostic actions on the API. This could lead to exposure of directory structure details, revealing distinguished names and attribute names of entries, while not disclosing attribute values themselves. Deployments without a configured LDAP Source remain unaffected by this issue. The vulnerability has been addressed in newer software releases.

Affected Version(s)

authentik < 2026.2.6 < 2026.2.6

authentik >= 2026.5.0, < 2026.5.5 < 2026.5.0, 2026.5.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.