#VU127138 Incorrect authorization in authentik - CVE-2024-47077
Published: September 27, 2024 / Updated: April 23, 2026
authentik
Authentik Security Inc
Description
The vulnerability allows a remote user to gain unauthorized access to another application's resources.
The vulnerability exists due to incorrect authorization in the /application/o/introspect/ endpoint when validating bearer tokens during token introspection. A remote user can present an access token issued for one application to impersonate the user against another application and gain unauthorized access to another application's resources.