Open-Source Identity Provider Vulnerability in Authentik
CVE-2026-94611
What is CVE-2026-94611?
Authentik, an open-source identity provider, has a security issue in its API serializers where stored credentials can be unintentionally exposed. Accounts with view permission may access sensitive credentials, even if they lack the authorization to modify configurations or view secrets. This vulnerability affects various configurations, including code delivery via email/SMS, outbound provisioning, integrations, and applications using client or shared secrets. It is important to note that deployments are only vulnerable when view permissions are granted to unauthorized accounts. This issue has been resolved in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Affected Version(s)
authentik < 2026.2.7 < 2026.2.7
authentik >= 2026.5.0, < 2026.5.7 < 2026.5.0, 2026.5.7
authentik >= 2026.8.0, < 2026.8.2 < 2026.8.0, 2026.8.2
