Vulnerability in Authentik Identity Provider Allowing Unauthenticated Message Submissions
CVE-2026-94613
What is CVE-2026-94613?
Prior to specified versions, an vulnerability in Authentik allowed an unauthenticated attacker to send specially crafted SAML messages. This caused the associated worker processes handling SAML requests to terminate unexpectedly. Consequently, legitimate traffic could be disrupted as the affected worker processes were unable to function properly. Importantly, if the worker processes were restarted, pre-existing sessions backed by databases were not destroyed, allowing for ongoing disruptions unless the malicious traffic was mitigated. This vulnerability is resolved in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Affected Version(s)
authentik < 2026.2.7 < 2026.2.7
authentik >= 2026.5.0, < 2026.5.7 < 2026.5.0, 2026.5.7
authentik >= 2026.8.0, < 2026.8.2 < 2026.8.0, 2026.8.2
