Executive brief
Authentik is an open-source authentication and authorization platform used to manage user access and identity. A flaw in its SCIM provisioning system allows an attacker with limited provisioning credentials to take over any user account, including administrator accounts, by creating matching SCIM users. This could result in complete compromise of the authentication system and unauthorized access to protected applications.
Technical details
The vulnerability is a privilege escalation flaw in Authentik's SCIM user provisioning function that fails to enforce scope boundaries when adopting pre-existing local accounts. An attacker with a source-scoped SCIM provisioning token can provision a SCIM user that matches an existing local username, causing the system to adopt the local account without validating that the provisioning token has authority over that account. This allows the attacker to rewrite or delete any account, including superuser accounts, using only limited provisioning credentials. The vulnerability affects Authentik through version 2026.5.6; patches or fixes should be available in later releases.
Affected products
- Authentik Security authentik through 2026.5.6
Timeline
- 2026-08-11: disclosed