CVEs we hold for Goauthentik
Records whose assigning authority named Goauthentik as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-54730authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and…goauthentik authentik
CVE-2026-49443authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the APIgoauthentik authentik
CVE-2026-47201authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated usergoauthentik authentik
CVE-2026-42849authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeovergoauthentik authentik
CVE-2026-41577authentik: SAML source does not validate Conditions, timing, or audience on assertionsgoauthentik authentik
CVE-2026-41569authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpointsgoauthentik authentik
CVE-2026-40172authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superusergoauthentik authentik
CVE-2026-40166authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/goauthentik authentik
CVE-2026-40165authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncationgoauthentik authentik
CVE-2026-25922authentik has a Signature Verification Bypass via SAML Assertion Wrappinggoauthentik authentik
CVE-2026-25227authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpointgoauthentik authentik
CVE-2025-53942authentik has an insufficient check for account active status during OAuth/SAML authenticationgoauthentik authentik
CVE-2025-52553authentik has Insufficient Session verification for Remote Access Control endpoint accessgoauthentik authentik
CVE-2025-29928authentik's deletion of sessions did not revoke sessions when using database session storagegoauthentik authentik
CVE-2024-52307authentik allows a timing attack due to missing constant time comparison for metrics viewgoauthentik authentik
CVE-2024-52289authentik has an insecure default configuration for OAuth2 Redirect URIsgoauthentik authentik
CVE-2024-47070authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headergoauthentik authentik
CVE-2024-42490authentik has Insufficient Authorization for several API endpointsgoauthentik authentik
CVE-2024-38371Insufficient access control for OAuth2 Device Code flow in authentikgoauthentik authentik
CVE-2024-37905Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentikgoauthentik authentik
CVE-2024-21637XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Modegoauthentik authentik
CVE-2023-46249authentik potential installation takeover when default admin user is deletedgoauthentik authentik
CVE-2022-46172authentik allows existing authenticated users to create arbitrary accountsgoauthentik authentik
CVE-2022-46145authentik vulnerable to unauthorized user creation and potential account takeovergoauthentik authentik
CVE-2022-23555authentik vulnerable to Improper Authentication via invitation URL token reusegoauthentik authentik
40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.