#VU127137 Improper Authentication in authentik - CVE-2024-47070
Published: September 27, 2024 / Updated: April 23, 2026
authentik
Authentik Security Inc
Description
The vulnerability allows a remote attacker to bypass authentication and authorize as any account with a known login or email address.
The vulnerability exists due to improper authentication in authentication and authorization flows when processing an X-Forwarded-For header with an unparsable IP address. A remote attacker can send a specially crafted request with a malformed X-Forwarded-For header to bypass authentication and authorize as any account with a known login or email address.
Exploitation is possible when the X-Forwarded-For header is not correctly controlled and policies are bound to authentication or authorization flows.