goauthentik records
33 published records for vendor goauthentik.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 24.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-284 Improper Access Control2
- CWE-269 Improper Privilege Management2
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-285 Improper Authorization2
The weakness classes this vendor ships most often: where to look.
CWEAll records
33 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-46145No exploit | authentik vulnerable to unauthorized user creation and potential account takeovergoauthentik · authentik · CWE-287 | Critical9.8 | — | 1.3% | Dec 2, 2022 |
39Monitor | CVE-2023-48228No exploit | OAuth2: PKCE can be fully circumventedgoauthentik · authentik · CWE-287 | Critical9.8 | — | 1.2% | Nov 21, 2023 |
39Monitor | CVE-2023-46249No exploit | authentik potential installation takeover when default admin user is deletedgoauthentik · authentik · CWE-287 | Critical9.8 | — | 0.7% | Oct 31, 2023 |
39Monitor | CVE-2026-49448No exploit | authentik: SourceStage bypass via empty POSTgoauthentik · authentik · CWE-287 | Critical9.8 | — | 0.6% | Jun 2, 2026 |
39Monitor | CVE-2024-38371No exploit | Insufficient access control for OAuth2 Device Code flow in authentikgoauthentik · authentik · CWE-284 | Critical9.8 | — | 0.6% | Jun 28, 2024 |
37Monitor | CVE-2026-42849No exploit | authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeovergoauthentik · authentik · CWE-79 | Critical9.3 | — | 0.5% | Jun 2, 2026 |
36Monitor | CVE-2024-47070No exploit | authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headergoauthentik · authentik · CWE-287 | Critical9.0 | — | 0.6% | Sep 27, 2024 |
35Monitor | CVE-2022-23555No exploit | authentik vulnerable to Improper Authentication via invitation URL token reusegoauthentik · authentik · CWE-287 | High8.8 | — | 0.9% | Dec 27, 2022 |
35Monitor | CVE-2024-37905No exploit | Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentikgoauthentik · authentik · CWE-284 | High8.8 | — | 0.8% | Jun 28, 2024 |
35Monitor | CVE-2024-23647No exploit | PKCE downgrade attack in Authentikgoauthentik · authentik · CWE-287 | High8.8 | — | 0.5% | Jan 30, 2024 |
35Monitor | CVE-2026-49443No exploit | authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the APIgoauthentik · authentik · CWE-287 | High8.8 | — | 0.4% | Jun 2, 2026 |
35Monitor | CVE-2026-25922No exploit | authentik has a Signature Verification Bypass via SAML Assertion Wrappinggoauthentik · authentik · CWE-287 | High8.8 | — | 0.3% | Feb 12, 2026 |
34Monitor | CVE-2026-47201No exploit | authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated usergoauthentik · authentik · CWE-20 | High8.5 | — | 0.3% | Jun 2, 2026 |
32Monitor | CVE-2025-29928No exploit | authentik's deletion of sessions did not revoke sessions when using database session storagegoauthentik · authentik · CWE-384 | High8.0 | — | 0.4% | Mar 28, 2025 |
31Monitor | CVE-2024-52289No exploit | authentik has an insecure default configuration for OAuth2 Redirect URIsgoauthentik · authentik · CWE-185 | High7.9 | — | 1.1% | Nov 21, 2024 |
30Monitor | CVE-2026-25748No exploit | authentik has a forward authentication bypass with broken cookiegoauthentik · authentik · CWE-287 | High7.5 | — | 0.9% | Feb 12, 2026 |
30Monitor | CVE-2024-42490No exploit | authentik has Insufficient Authorization for several API endpointsgoauthentik · authentik · CWE-285 | High7.5 | — | 0.5% | Aug 22, 2024 |
29Monitor | CVE-2023-36456No exploit | Authentik lacks Proxy IP headers validationgoauthentik · authentik · CWE-436 | High7.3 | — | 0.8% | Jul 6, 2023 |
28Monitor | CVE-2026-25227No exploit | authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpointgoauthentik · authentik · CWE-94 | High7.2 | — | 0.9% | Feb 12, 2026 |
28Monitor | CVE-2025-53942No exploit | authentik has an insufficient check for account active status during OAuth/SAML authenticationgoauthentik · authentik · CWE-269 | High7.1 | — | 0.5% | Jul 23, 2025 |
27Monitor | CVE-2026-41569No exploit | authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpointsgoauthentik · authentik · CWE-601 | Medium6.9 | — | 0.3% | Jun 2, 2026 |
27Monitor | CVE-2026-41577No exploit | authentik: SAML source does not validate Conditions, timing, or audience on assertionsgoauthentik · authentik · CWE-345 | Medium6.9 | — | 0.2% | Jun 2, 2026 |
26Monitor | CVE-2024-47077No exploit | authentik cross-provider token validation problemsgoauthentik · authentik · CWE-863 | Medium6.5 | — | 0.4% | Sep 27, 2024 |
26Monitor | CVE-2023-26481No exploit | Insufficient user check in FlowTokens by Email stagegoauthentik · authentik · CWE-345 | Medium6.5 | — | 0.3% | Mar 3, 2023 |
25Monitor | CVE-2024-52287No exploit | authentik performs insufficient validation of OAuth scopesgoauthentik · authentik · CWE-285 | Medium6.4 | — | 0.6% | Nov 21, 2024 |
- CVE-2022-4614539Monitor
authentik vulnerable to unauthorized user creation and potential account takeover
CriticalCVSS 9.8No exploitEPSS 1%goauthentik · authentikDec 2, 2022
- CVE-2023-4822839Monitor
OAuth2: PKCE can be fully circumvented
CriticalCVSS 9.8No exploitEPSS 1%goauthentik · authentikNov 21, 2023
- CVE-2023-4624939Monitor
authentik potential installation takeover when default admin user is deleted
CriticalCVSS 9.8No exploitEPSS 1%goauthentik · authentikOct 31, 2023
- CVE-2026-4944839Monitor
authentik: SourceStage bypass via empty POST
CriticalCVSS 9.8No exploitEPSS 1%goauthentik · authentikJun 2, 2026
- CVE-2024-3837139Monitor
Insufficient access control for OAuth2 Device Code flow in authentik
CriticalCVSS 9.8No exploitEPSS 1%goauthentik · authentikJun 28, 2024
- CVE-2026-4284937Monitor
authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover
CriticalCVSS 9.3No exploitEPSS 0%goauthentik · authentikJun 2, 2026
- CVE-2024-4707036Monitor
authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP header
CriticalCVSS 9.0No exploitEPSS 1%goauthentik · authentikSep 27, 2024
- CVE-2022-2355535Monitor
authentik vulnerable to Improper Authentication via invitation URL token reuse
HighCVSS 8.8No exploitEPSS 1%goauthentik · authentikDec 27, 2022
- CVE-2024-3790535Monitor
Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik
HighCVSS 8.8No exploitEPSS 1%goauthentik · authentikJun 28, 2024
- CVE-2024-2364735Monitor
PKCE downgrade attack in Authentik
HighCVSS 8.8No exploitEPSS 1%goauthentik · authentikJan 30, 2024
- CVE-2026-4944335Monitor
authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API
HighCVSS 8.8No exploitEPSS 0%goauthentik · authentikJun 2, 2026
- CVE-2026-2592235Monitor
authentik has a Signature Verification Bypass via SAML Assertion Wrapping
HighCVSS 8.8No exploitEPSS 0%goauthentik · authentikFeb 12, 2026
- CVE-2026-4720134Monitor
authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
HighCVSS 8.5No exploitEPSS 0%goauthentik · authentikJun 2, 2026
- CVE-2025-2992832Monitor
authentik's deletion of sessions did not revoke sessions when using database session storage
HighCVSS 8.0No exploitEPSS 0%goauthentik · authentikMar 28, 2025
- CVE-2024-5228931Monitor
authentik has an insecure default configuration for OAuth2 Redirect URIs
HighCVSS 7.9No exploitEPSS 1%goauthentik · authentikNov 21, 2024
- CVE-2026-2574830Monitor
authentik has a forward authentication bypass with broken cookie
HighCVSS 7.5No exploitEPSS 1%goauthentik · authentikFeb 12, 2026
- CVE-2024-4249030Monitor
authentik has Insufficient Authorization for several API endpoints
HighCVSS 7.5No exploitEPSS 0%goauthentik · authentikAug 22, 2024
- CVE-2023-3645629Monitor
Authentik lacks Proxy IP headers validation
HighCVSS 7.3No exploitEPSS 1%goauthentik · authentikJul 6, 2023
- CVE-2026-2522728Monitor
authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint
HighCVSS 7.2No exploitEPSS 1%goauthentik · authentikFeb 12, 2026
- CVE-2025-5394228Monitor
authentik has an insufficient check for account active status during OAuth/SAML authentication
HighCVSS 7.1No exploitEPSS 1%goauthentik · authentikJul 23, 2025
- CVE-2026-4156927Monitor
authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints
MediumCVSS 6.9No exploitEPSS 0%goauthentik · authentikJun 2, 2026
- CVE-2026-4157727Monitor
authentik: SAML source does not validate Conditions, timing, or audience on assertions
MediumCVSS 6.9No exploitEPSS 0%goauthentik · authentikJun 2, 2026
- CVE-2024-4707726Monitor
authentik cross-provider token validation problems
MediumCVSS 6.5No exploitEPSS 0%goauthentik · authentikSep 27, 2024
- CVE-2023-2648126Monitor
Insufficient user check in FlowTokens by Email stage
MediumCVSS 6.5No exploitEPSS 0%goauthentik · authentikMar 3, 2023
- CVE-2024-5228725Monitor
authentik performs insufficient validation of OAuth scopes
MediumCVSS 6.4No exploitEPSS 1%goauthentik · authentikNov 21, 2024