Email Authenticator Enrollment Vulnerability in Authentik by Goauthentik
CVE-2026-94606

8.9HIGH

Key Information:

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-94606?

The Authentik email authenticator enrollment process has a significant design flaw allowing an unauthorized actor to use a victim's email instead of the one initially set up. During the authentication or enrollment process, an attacker who has access to a user's password can manipulate the enrollment by substituting their own email address. This risks the victim’s security by allowing the attacker to receive one-time codes, ultimately leading to the unauthorized enrollment into the system and access to single sign-on applications linked to that user’s account. This vulnerability is addressed in the Authentik updates 2026.2.7, 2026.5.7, and 2026.8.2.

Affected Version(s)

authentik < 2026.2.7 < 2026.2.7

authentik >= 2026.5.0, < 2026.5.7 < 2026.5.0, 2026.5.7

authentik >= 2026.8.0, < 2026.8.2 < 2026.8.0, 2026.8.2

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.