#VU127140 Incorrect authorization in authentik - CVE-2024-37905
Published: June 26, 2024 / Updated: April 23, 2026
authentik
Authentik Security Inc
Description
The vulnerability allows a remote user to escalate privileges to superuser.
The vulnerability exists due to incorrect authorization in the API token management endpoint when handling token modification requests. A remote user can create an API token and change the user the token belongs to to escalate privileges to superuser.
The modified token inherits the API access of the higher-privileged user, which can enable password changes for that user or malicious configuration changes.