Open-Source Identity Provider Vulnerability in Authentik
CVE-2026-94611

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-94611?

Authentik, an open-source identity provider, has a security issue in its API serializers where stored credentials can be unintentionally exposed. Accounts with view permission may access sensitive credentials, even if they lack the authorization to modify configurations or view secrets. This vulnerability affects various configurations, including code delivery via email/SMS, outbound provisioning, integrations, and applications using client or shared secrets. It is important to note that deployments are only vulnerable when view permissions are granted to unauthorized accounts. This issue has been resolved in versions 2026.2.7, 2026.5.7, and 2026.8.2.

Affected Version(s)

authentik < 2026.2.7 < 2026.2.7

authentik >= 2026.5.0, < 2026.5.7 < 2026.5.0, 2026.5.7

authentik >= 2026.8.0, < 2026.8.2 < 2026.8.0, 2026.8.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.