vciy

CVEs we hold for Goauthentik

Records whose assigning authority named Goauthentik as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-61574authentik RAC: access any endpoint via an unrelated applicationgoauthentik authentik
CVE-2026-57580authentik: Account Takeover via SAML NameID Comment Truncationgoauthentik authentik
CVE-2026-55106authentik: Unauthenticated LDAP directory data disclosuregoauthentik authentik
CVE-2026-54730authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and…goauthentik authentik
CVE-2026-49448authentik: SourceStage bypass via empty POSTgoauthentik authentik
CVE-2026-49443authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the APIgoauthentik authentik
CVE-2026-47201authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated usergoauthentik authentik
CVE-2026-42849authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeovergoauthentik authentik
CVE-2026-41577authentik: SAML source does not validate Conditions, timing, or audience on assertionsgoauthentik authentik
CVE-2026-41569authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpointsgoauthentik authentik
CVE-2026-40172authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superusergoauthentik authentik
CVE-2026-40166authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/goauthentik authentik
CVE-2026-40165authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncationgoauthentik authentik
CVE-2026-25922authentik has a Signature Verification Bypass via SAML Assertion Wrappinggoauthentik authentik
CVE-2026-25748authentik has a forward authentication bypass with broken cookiegoauthentik authentik
CVE-2026-25227authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpointgoauthentik authentik
CVE-2025-64708authentik invitation expiry is delayed by at least 5 minutesgoauthentik authentik
CVE-2025-64521authentik deactivated service accounts can authenticate to OAuthgoauthentik authentik
CVE-2025-53942authentik has an insufficient check for account active status during OAuth/SAML authenticationgoauthentik authentik
CVE-2025-52553authentik has Insufficient Session verification for Remote Access Control endpoint accessgoauthentik authentik
CVE-2025-29928authentik's deletion of sessions did not revoke sessions when using database session storagegoauthentik authentik
CVE-2024-52307authentik allows a timing attack due to missing constant time comparison for metrics viewgoauthentik authentik
CVE-2024-52289authentik has an insecure default configuration for OAuth2 Redirect URIsgoauthentik authentik
CVE-2024-52287authentik performs insufficient validation of OAuth scopesgoauthentik authentik
CVE-2024-47077authentik cross-provider token validation problemsgoauthentik authentik
CVE-2024-47070authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headergoauthentik authentik
CVE-2024-42490authentik has Insufficient Authorization for several API endpointsgoauthentik authentik
CVE-2024-38371Insufficient access control for OAuth2 Device Code flow in authentikgoauthentik authentik
CVE-2024-37905Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentikgoauthentik authentik
CVE-2024-23647PKCE downgrade attack in Authentikgoauthentik authentik
CVE-2024-21637XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Modegoauthentik authentik
CVE-2024-11623Stored XSS in authentikgoauthentik authentik
CVE-2023-48228OAuth2: PKCE can be fully circumventedgoauthentik authentik
CVE-2023-46249authentik potential installation takeover when default admin user is deletedgoauthentik authentik
CVE-2023-39522Username enumeration attack in goauthentikgoauthentik authentik
CVE-2023-36456Authentik lacks Proxy IP headers validationgoauthentik authentik
CVE-2023-26481Insufficient user check in FlowTokens by Email stagegoauthentik authentik
CVE-2022-46172authentik allows existing authenticated users to create arbitrary accountsgoauthentik authentik
CVE-2022-46145authentik vulnerable to unauthorized user creation and potential account takeovergoauthentik authentik
CVE-2022-23555authentik vulnerable to Improper Authentication via invitation URL token reusegoauthentik authentik

40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.