Junglewise Threat Intelligence

CVE-2026-72534: Authentik privilege escalation via SCIM provisioning

CVE-2026-72534 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Authentik Security Authentik.

Executive brief

Authentik is an identity provider and access management platform. A vulnerability allows an attacker with limited SCIM provisioning credentials to gain full administrative privileges by creating a SCIM group that matches an existing administrator group name, bypassing access controls and potentially locking out all legitimate administrators.

Technical details

The vulnerability is a privilege escalation in Authentik's SCIM group provisioning function. The root cause is improper validation of source scope constraints when ingesting SCIM groups; the system adopts existing groups by name and replaces membership without verifying that the provisioning token's scope permits access to that group. An attacker with a source-scoped SCIM provisioning token can send a malicious SCIM request creating a group matching an existing administrator group name, which causes the system to merge the attacker-controlled membership into the privileged group. No special preconditions beyond token possession are required. The attacker gains full IdP superuser access and can lock out all existing administrators. A patch is available in versions after 2026.5.6.

Affected products

  • Authentik Security authentik through 2026.5.6

Timeline

  • 2026-08-11: disclosed

References