SAML Source Vulnerability in Authentik Identity Provider
CVE-2026-94612

7.4HIGH

Key Information:

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-94612?

An unauthenticated actor could exploit a flaw in Authentik's SAML Source by reusing a valid assertion meant for another service provider. The SAML Source verified an assertion’s signature and validity period without confirming the assertion originated from the appropriate identity provider or as part of a login request. Additionally, the SAML Source lacked the functionality to record accepted assertions, paving the way for potential replay attacks. This issue affects only SAML Sources, while SAML Providers and other source types remain secure. Fixes are available in versions 2026.2.7, 2026.5.7, and 2026.8.2.

Affected Version(s)

authentik < 2026.2.7 < 2026.2.7

authentik >= 2026.5.0, < 2026.5.7 < 2026.5.0, 2026.5.7

authentik >= 2026.8.0, < 2026.8.2 < 2026.8.0, 2026.8.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.