Executive brief
authentik allows a deactivated Service account to authenticate to OAuth in goauthentik.io
Affected products
- Go goauthentik.io
- PyPI authentik-client
Junglewise Threat Intelligence
CVE-2025-64521 · Severity: low · CVSS 3.1 · Published 2025-12-15
Technologies: goauthentik.io (Go). Vendors: Go, PyPI.
authentik allows a deactivated Service account to authenticate to OAuth in goauthentik.io