#VU127138 Incorrect authorization in authentik - CVE-2024-47077

 

#VU127138 Incorrect authorization in authentik - CVE-2024-47077

Published: September 27, 2024 / Updated: April 23, 2026


Vulnerability identifier: #VU127138
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-47077
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
authentik
Software vendor:
Authentik Security Inc

Description

The vulnerability allows a remote user to gain unauthorized access to another application's resources.

The vulnerability exists due to incorrect authorization in the /application/o/introspect/ endpoint when validating bearer tokens during token introspection. A remote user can present an access token issued for one application to impersonate the user against another application and gain unauthorized access to another application's resources.


Remediation

Install security update from vendor's website.

External links