CVE-2026-47201
8.5 HIGHauthentik is an open-source identity provider
Published: 2026-06-02 · Last updated: 2026-06-04
Severity and scoring
- CVSS
- 8.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-20, CWE-347
Affected products
| Vendor | Product |
|---|---|
| goauthentik | authentik |
Description
authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue has been patched in versions 2025.12.5, 2026.2.3, and 2026.5.1.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2026-49448 — authentik is an open-source identity provider (9.8 CRITICAL)
- CVE-2026-49443 — authentik is an open-source identity provider (8.8 HIGH)
- CVE-2026-42849 — authentik is an open-source identity provider (9.3 CRITICAL)
- CVE-2026-41569 — authentik is an open-source identity provider (6.1 MEDIUM)
- CVE-2026-41577 — authentik is an open-source identity provider (7.5 HIGH)
Same CWE
- CVE-2026-45329 — ESF-IDF is the Espressif Internet of Things (IOT) Development Framework (7.1 HIGH)
- CVE-2026-45328 — ESF-IDF is the Espressif Internet of Things (IOT) Development Framework (9.3 CRITICAL)
- CVE-2026-41727 — Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them (6.5 MEDIUM)
- CVE-2026-41694 — Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a val... (3.7 LOW)
- CVE-2026-47903 — CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability (6.2 MEDIUM)