Skip to content
Noroxi

goauthentik records

33 published records for vendor goauthentik.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
24.2%
Median publish → KEV
No record has entered KEV

All records

33 records
  • authentik vulnerable to unauthorized user creation and potential account takeover

    CriticalCVSS 9.8No exploitEPSS 1%

    goauthentik · authentikDec 2, 2022

  • OAuth2: PKCE can be fully circumvented

    CriticalCVSS 9.8No exploitEPSS 1%

    goauthentik · authentikNov 21, 2023

  • authentik potential installation takeover when default admin user is deleted

    CriticalCVSS 9.8No exploitEPSS 1%

    goauthentik · authentikOct 31, 2023

  • authentik: SourceStage bypass via empty POST

    CriticalCVSS 9.8No exploitEPSS 1%

    goauthentik · authentikJun 2, 2026

  • Insufficient access control for OAuth2 Device Code flow in authentik

    CriticalCVSS 9.8No exploitEPSS 1%

    goauthentik · authentikJun 28, 2024

  • authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover

    CriticalCVSS 9.3No exploitEPSS 0%

    goauthentik · authentikJun 2, 2026

  • authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP header

    CriticalCVSS 9.0No exploitEPSS 1%

    goauthentik · authentikSep 27, 2024

  • authentik vulnerable to Improper Authentication via invitation URL token reuse

    HighCVSS 8.8No exploitEPSS 1%

    goauthentik · authentikDec 27, 2022

  • Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik

    HighCVSS 8.8No exploitEPSS 1%

    goauthentik · authentikJun 28, 2024

  • PKCE downgrade attack in Authentik

    HighCVSS 8.8No exploitEPSS 1%

    goauthentik · authentikJan 30, 2024

  • authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API

    HighCVSS 8.8No exploitEPSS 0%

    goauthentik · authentikJun 2, 2026

  • authentik has a Signature Verification Bypass via SAML Assertion Wrapping

    HighCVSS 8.8No exploitEPSS 0%

    goauthentik · authentikFeb 12, 2026

  • authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user

    HighCVSS 8.5No exploitEPSS 0%

    goauthentik · authentikJun 2, 2026

  • authentik's deletion of sessions did not revoke sessions when using database session storage

    HighCVSS 8.0No exploitEPSS 0%

    goauthentik · authentikMar 28, 2025

  • authentik has an insecure default configuration for OAuth2 Redirect URIs

    HighCVSS 7.9No exploitEPSS 1%

    goauthentik · authentikNov 21, 2024

  • authentik has a forward authentication bypass with broken cookie

    HighCVSS 7.5No exploitEPSS 1%

    goauthentik · authentikFeb 12, 2026

  • authentik has Insufficient Authorization for several API endpoints

    HighCVSS 7.5No exploitEPSS 0%

    goauthentik · authentikAug 22, 2024

  • Authentik lacks Proxy IP headers validation

    HighCVSS 7.3No exploitEPSS 1%

    goauthentik · authentikJul 6, 2023

  • authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint

    HighCVSS 7.2No exploitEPSS 1%

    goauthentik · authentikFeb 12, 2026

  • authentik has an insufficient check for account active status during OAuth/SAML authentication

    HighCVSS 7.1No exploitEPSS 1%

    goauthentik · authentikJul 23, 2025

  • authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints

    MediumCVSS 6.9No exploitEPSS 0%

    goauthentik · authentikJun 2, 2026

  • authentik: SAML source does not validate Conditions, timing, or audience on assertions

    MediumCVSS 6.9No exploitEPSS 0%

    goauthentik · authentikJun 2, 2026

  • authentik cross-provider token validation problems

    MediumCVSS 6.5No exploitEPSS 0%

    goauthentik · authentikSep 27, 2024

  • Insufficient user check in FlowTokens by Email stage

    MediumCVSS 6.5No exploitEPSS 0%

    goauthentik · authentikMar 3, 2023

  • authentik performs insufficient validation of OAuth scopes

    MediumCVSS 6.4No exploitEPSS 1%

    goauthentik · authentikNov 21, 2024