Observable Response Discrepancy in authentik - CVE-2023-39522
Published: August 29, 2023 / Updated: April 23, 2026
authentik
Authentik Security Inc
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable response discrepancy in the recovery flow identification stage when handling recovery flow requests. A remote attacker can submit crafted username or email values to disclose sensitive information.
Only setups configured with a recovery flow are vulnerable, and enumeration may be possible by username, email, or both depending on configuration.