Privilege Escalation Vulnerability in Authentik Security Affecting User Accounts
CVE-2026-72537

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72537?

A vulnerability in Authentik Security allows attackers with a source-scoped SCIM provisioning token to gain unauthorized access to user accounts, including superuser accounts. This is possible by creating a SCIM user that matches the username of an existing local user, bypassing scope validations. The risky SCIM user ingestion process permits the modification or deletion of user accounts using only limited provisioning credentials, presenting significant security risks.

Affected Version(s)

authentik 0 <= 2026.5.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov (Mahadsec)
.