Email Authenticator Enrollment Vulnerability in Authentik by Goauthentik
CVE-2026-94606
What is CVE-2026-94606?
The Authentik email authenticator enrollment process has a significant design flaw allowing an unauthorized actor to use a victim's email instead of the one initially set up. During the authentication or enrollment process, an attacker who has access to a user's password can manipulate the enrollment by substituting their own email address. This risks the victim’s security by allowing the attacker to receive one-time codes, ultimately leading to the unauthorized enrollment into the system and access to single sign-on applications linked to that user’s account. This vulnerability is addressed in the Authentik updates 2026.2.7, 2026.5.7, and 2026.8.2.
Affected Version(s)
authentik < 2026.2.7 < 2026.2.7
authentik >= 2026.5.0, < 2026.5.7 < 2026.5.0, 2026.5.7
authentik >= 2026.8.0, < 2026.8.2 < 2026.8.0, 2026.8.2
