Executive brief
Authentik is an identity provider and access management platform. A vulnerability allows an attacker with limited SCIM provisioning credentials to gain full administrative privileges by creating a SCIM group that matches an existing administrator group name, bypassing access controls and potentially locking out all legitimate administrators.
Technical details
The vulnerability is a privilege escalation in Authentik's SCIM group provisioning function. The root cause is improper validation of source scope constraints when ingesting SCIM groups; the system adopts existing groups by name and replaces membership without verifying that the provisioning token's scope permits access to that group. An attacker with a source-scoped SCIM provisioning token can send a malicious SCIM request creating a group matching an existing administrator group name, which causes the system to merge the attacker-controlled membership into the privileged group. No special preconditions beyond token possession are required. The attacker gains full IdP superuser access and can lock out all existing administrators. A patch is available in versions after 2026.5.6.
Affected products
- Authentik Security authentik through 2026.5.6
Timeline
- 2026-08-11: disclosed