Vulnerability in Authentik Identity Provider Allowing Unauthenticated Message Submissions
CVE-2026-94613

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-94613?

Prior to specified versions, an vulnerability in Authentik allowed an unauthenticated attacker to send specially crafted SAML messages. This caused the associated worker processes handling SAML requests to terminate unexpectedly. Consequently, legitimate traffic could be disrupted as the affected worker processes were unable to function properly. Importantly, if the worker processes were restarted, pre-existing sessions backed by databases were not destroyed, allowing for ongoing disruptions unless the malicious traffic was mitigated. This vulnerability is resolved in versions 2026.2.7, 2026.5.7, and 2026.8.2.

Affected Version(s)

authentik < 2026.2.7 < 2026.2.7

authentik >= 2026.5.0, < 2026.5.7 < 2026.5.0, 2026.5.7

authentik >= 2026.8.0, < 2026.8.2 < 2026.8.0, 2026.8.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.