QSearchQSearch

CVE-2026-41577

7.5 HIGH

authentik is an open-source identity provider

Published: 2026-06-02 · Last updated: 2026-06-04

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE
CWE-345

Affected products

VendorProduct
goauthentikauthentik

Description

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored. This allows replay of expired assertions and acceptance of assertions intended for other service providers. This issue has been patched in versions 2025.12.5 and 2026.2.3.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-49448 authentik is an open-source identity provider (9.8 CRITICAL)
  • CVE-2026-49443 authentik is an open-source identity provider (8.8 HIGH)
  • CVE-2026-47201 authentik is an open-source identity provider (8.5 HIGH)
  • CVE-2026-42849 authentik is an open-source identity provider (9.3 CRITICAL)
  • CVE-2026-41569 authentik is an open-source identity provider (6.1 MEDIUM)

Same CWE

  • CVE-2026-46539 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm (5.9 MEDIUM)
  • CVE-2026-7792 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insuf... (5.3 MEDIUM)
  • CVE-2026-8608 The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Au... (5.3 MEDIUM)
  • CVE-2026-50214 The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero... (9.8 CRITICAL)
  • CVE-2022-4992 Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partiall... (8.6 HIGH)