Executive brief
authentik is an open-source identity provider used to manage user authentication and single sign-on. A security flaw in how it handles login requests from external providers allows an attacker with a valid account to impersonate other users. This could lead to unauthorized access to sensitive corporate data or administrative accounts, potentially resulting in a full system compromise.
Technical details
The authentik SAML Source Assertion Consumer Service (ACS) endpoint is vulnerable to XML Signature Wrapping (XSW). The root cause is a failure to ensure that the verified XML signature strictly corresponds to the specific SAML assertion being processed for identity data. An attacker with a valid account at an upstream Identity Provider (IdP) can capture a legitimate signed SAML response and modify it to include a forged assertion. By wrapping the valid signature such that it still passes verification while the application logic processes the forged assertion, the attacker can authenticate as any other federated user or local user. This vulnerability has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.
Affected products
- goauthentik authentik < 2025.12.6, < 2026.2.4, < 2026.5.1
Timeline
- 2026-05-28: advisory: Vendor advisory published on GitHub
- 2026-06-02: disclosed: CVE published to NVD