Junglewise Threat Intelligence

CVE-2025-64521: GO-2025-4137 - authentik allows a deactivated Service account to authenticate to OAuth in goauthentik.io

CVE-2025-64521 · Severity: low · CVSS 3.1 · Published 2025-12-15

Technologies: goauthentik.io (Go). Vendors: Go, PyPI.

Executive brief

authentik allows a deactivated Service account to authenticate to OAuth in goauthentik.io

Affected products

  • Go goauthentik.io
  • PyPI authentik-client

Related threats