SB2026090968 - Multiple vulnerabilities in authentik
Published: September 9, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2026-94613)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of malformed SAML messages in the SAML message handling worker when processing specially formed SAML messages. A remote attacker can send a specially formed SAML message to cause a denial of service.
Only deployments using SAML in identity provider or source roles are affected. Worker processes are automatically restarted, and sessions survive because they are stored in the database.
2) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: CVE-2026-94606)
CWE-ID: CWE-807 - Reliance on Untrusted Inputs in a Security Decision
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass multi-factor authentication and sign in as another user.
The vulnerability exists due to reliance on untrusted input in a security decision in the email authenticator setup process when processing an authenticator setup request. A remote attacker can supply an email address they control and use the delivered one-time code to sign in as the target user.
Exploitation requires knowledge of the target user's password, an unenrolled email factor, and a deployment that enrolls the email authenticator during an authentication or enrollment flow.
3) Incorrect authorization (CVE-ID: CVE-2026-94609)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to incorrect authorization in delegated group and user management when managing delegated groups or users. A remote user can grant superuser status to an account or assign an existing role to a group to escalate privileges.
Only deployments that delegate group, group membership, or user management to non-administrator accounts are affected.
Remediation
Install update from vendor's website.