Known vulnerabilities in authentik
Vendor:
Authentik Security Inc
Software:
authentik
Software CPE:
cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*
Website:
https://goauthentik.io/
Total vulnerabilities:
42
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2026.5.6
2026.5.5
2026.2.6
2026.5.4
2026.2.5
2026.5.3
2026.5.2
2026.2.4
2025.12.6
2026.5.0
2025.12.5
2026.2.3
2026.2.2
2026.2.1
2026.2.0
2025.12.4
2025.10.4
2025.8.6
2025.12.3
2025.12.2
2025.12.1
2025.12.0
2025.10.3
2025.8.5
2025.10.2
2025.10.1
2025.10.0
2025.8.4
2025.8.3
2025.8.2
2025.8.1
2025.8.0
2025.6.4
2025.4.4
2025.6.3
2025.4.3
2025.6.2
2025.6.1
2025.4.2
2025.6.0
2025.4.1
2025.4.0
2025.2.4
2024.12.5
2025.2.3
2024.12.4
2025.2.2
2025.2.1
2025.2.0
2024.12.3
2024.12.2
2024.12.1
2024.12.0
2024.10.5
2024.10.4
2024.10.3
2024.8.6
2024.8.5
2024.10.2
2024.10.1
2024.10.0
2024.8.4
2024.8.3
2024.6.5
2024.8.2
2024.8.1
2024.8.0
2024.6.4
2024.4.4
2024.6.3
2024.6.2
2024.6.1
2024.6.0
2024.4.3
2024.2.4
2024.4.2
2024.4.1
2024.4.0
2024.2.3
2024.2.2
2024.2.1
2024.2.0
2023.10.7
2023.8.7
2023.10.6
2023.8.6
2023.10.5
2023.10.4
2023.8.5
2023.10.3
2023.10.2
2023.10.1
2023.10.0
2023.8.4
2023.8.3
2023.8.2
2023.8.1
2023.8.0
2023.6.2
2023.6.1
2023.6.0
2023.5.6
2023.5.5
2023.5.4
2023.5.3
2023.5.2
2023.5.1
2023.5.0
2023.4.3
2023.4.2
2023.4.1
2023.4.0
2023.3.1
2023.3.0
2023.2.3
2023.2.2
2023.2.1
2023.2.0
2023.1.3
2023.1.2
2023.1.1
2023.1.0
2022.12.3
2022.12.2
2022.12.1
2022.12.0
2022.11.4
2022.11.3
2022.11.2
2022.11.1
2022.11.0
2022.10.4
2022.10.3
2022.10.2
2022.10.1
2022.10.0
2022.9.0
2022.8.2
2022.8.1
2022.7.3
2022.7.2
2022.7.1
2022.6.3
2022.6.2
2022.6.1
2022.5.3
2022.5.2
2022.5.1
2022.4.1
2022.3.3
2022.3.2
2022.3.1
2022.2.1
2022.1.5
2022.1.4
2022.1.3
2022.1.2
2022.1.1
2021.12.5
2021.12.4
2021.12.3
2021.12.2
2021.12.1
2021.10.4
2021.10.3
2021.10.2
2021.10.1
2021.9.8
2021.9.7
2021.9.6
2021.9.5
2021.9.4
2021.9.3
2021.9.2
2021.9.1
2021.8.5
2021.8.4
2021.8.3
2021.8.2
2021.8.1
2021.7.3
2021.7.2
2021.7.1
2021.6.4
2021.6.3
2021.6.2
2021.6.1
2021.5.4
2021.5.3
2021.5.2
2021.5.1
2021.4.6
2021.4.5
2021.4.4
2021.4.3
2021.4.2
2021.4.1
2021.3.4
2021.3.3
2021.3.2
2021.3.1
Vulnerabilities (42)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU138386 - Missing Authorization |
CWE-862 | Low | 2026.2.6, 2026.5.5 | 17.07.2026 |
SB20260717100 |
||
| #VU138385 - Improper Access Control CVE-2026-54730 |
CWE-284 | Low | 2026.2.6, 2026.5.5 | 17.07.2026 |
SB20260717100 |
||
| #VU138384 - Authorization Bypass Through User-Controlled Key CVE-2026-61574 |
CWE-639 | Medium | 2026.2.6, 2026.5.5 | 17.07.2026 |
SB20260717100 |
||
| #VU138383 - Improper Access Control CVE-2026-55106 |
CWE-284 | Medium | 2026.2.6, 2026.5.5 | 17.07.2026 |
SB20260717100 |
||
| #VU138382 - Interpretation Conflict CVE-2026-57580 |
CWE-436 | High | 2026.2.6, 2026.5.5 | 17.07.2026 |
SB20260717100 |
||
| #VU132754 - Improper Verification of Cryptographic Signature CVE-2026-47201 |
CWE-347 | Medium | 2025.12.6, 2026.2.4, 2026.5.2 | 29.05.2026 |
SB2026052928 |
||
| #VU132753 - Improper Access Control CVE-2026-49443 |
CWE-284 | Medium | 2025.12.6, 2026.2.4, 2026.5.2 | 29.05.2026 |
SB2026052928 |
||
| #VU132752 - Incorrect Authorization CVE-2026-49448 |
CWE-863 | High | 2025.12.6, 2026.2.4, 2026.5.2 | 29.05.2026 |
SB2026052928 |
||
| #VU131253 - Improper Privilege Management CVE-2026-40172 |
CWE-269 | Medium | 2025.12.5, 2026.2.3 | 12.05.2026 |
SB20260512112 |
||
| #VU131252 - Improper Access Control |
CWE-284 | Medium | 2025.12.5, 2026.2.3 | 12.05.2026 |
SB20260512112 |
||
| #VU131251 - Insufficient Verification of Data Authenticity CVE-2026-41577 |
CWE-345 | Low | 2025.4.0 | 12.05.2026 |
SB20260512114 |
||
| #VU131250 - Incorrect Authorization CVE-2026-40166 |
CWE-863 | Low | 2025.12.5, 2026.2.3 | 12.05.2026 |
SB20260512112 |
||
| #VU131248 - Improper Access Control |
CWE-284 | High | 2025.12.5, 2026.2.3 | 12.05.2026 |
SB20260512112 |
||
| #VU131247 - Improper input validation CVE-2026-40165 |
CWE-20 | High | 2025.12.5, 2026.2.3 | 12.05.2026 |
SB20260512112 |
||
| #VU131246 - Improper input validation CVE-2026-41569 |
CWE-20 | Low | 2026.2.3 | 12.05.2026 |
SB20260512112 |
||
| #VU131245 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-42849 |
CWE-79 | Medium | 2025.12.5, 2026.2.3 | 12.05.2026 |
SB20260512112 |
||
| #VU127149 - Improper Authentication CVE-2026-25748 |
CWE-287 | High | 2025.10.4, 2025.12.4 | 23.04.2026 |
SB20260423142 |
||
| #VU127148 - Improper Control of Generation of Code ('Code Injection') CVE-2026-25227 |
CWE-94 | Low | 2025.8.6, 2025.10.4, 2025.12.4 | 23.04.2026 |
SB20260423142 |
||
| #VU127147 - Improper Verification of Cryptographic Signature CVE-2026-25922 |
CWE-347 | Medium | 2025.8.6, 2025.10.4, 2025.12.4 | 23.04.2026 |
SB20260423142 |
||
| #VU118626 - Improper Authentication CVE-2025-64521 |
CWE-287 | Low | 2025.8.5, 2025.10.2 | 19.11.2025 |
SB2025111950 |
Showing elements 1 - 20 out of 42