#VU127136 Improper Authorization in authentik - CVE-2024-52287
Published: November 21, 2024 / Updated: April 23, 2026
authentik
Authentik Security Inc
Description
The vulnerability allows a remote user to perform unauthorized actions in another system that trusts tokens signed by authentik.
The vulnerability exists due to improper authorization in OAuth scope validation for the client_credentials and device_code grants when issuing OAuth tokens. A remote privileged user can request or obtain a token with scopes not configured in authentik to perform unauthorized actions in another system that trusts tokens signed by authentik.
Exploitation requires valid OAuth2 client credentials and knowledge of a trusting downstream system and the scopes it checks for.