SB2026090968 - Multiple vulnerabilities in authentik



SB2026090968 - Multiple vulnerabilities in authentik

Published: September 9, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026090968
CSH Severity
High
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 33% Medium 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Input validation error (CVE-ID: CVE-2026-94613)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of malformed SAML messages in the SAML message handling worker when processing specially formed SAML messages. A remote attacker can send a specially formed SAML message to cause a denial of service.

Only deployments using SAML in identity provider or source roles are affected. Worker processes are automatically restarted, and sessions survive because they are stored in the database.


2) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: CVE-2026-94606)

CWE-ID: CWE-807 - Reliance on Untrusted Inputs in a Security Decision

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass multi-factor authentication and sign in as another user.

The vulnerability exists due to reliance on untrusted input in a security decision in the email authenticator setup process when processing an authenticator setup request. A remote attacker can supply an email address they control and use the delivered one-time code to sign in as the target user.

Exploitation requires knowledge of the target user's password, an unenrolled email factor, and a deployment that enrolls the email authenticator during an authentication or enrollment flow.


3) Incorrect authorization (CVE-ID: CVE-2026-94609)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to incorrect authorization in delegated group and user management when managing delegated groups or users. A remote user can grant superuser status to an account or assign an existing role to a group to escalate privileges.

Only deployments that delegate group, group membership, or user management to non-administrator accounts are affected.


Remediation

Install update from vendor's website.