Improper access control in authentik - CVE-2022-46145
Published: December 2, 2022 / Updated: April 23, 2026
authentik
Authentik Security Inc
Description
The vulnerability allows a remote attacker to create unauthorized accounts and potentially take over accounts.
The vulnerability exists due to improper access control in the default user settings flow when handling account creation and email-verified password recovery flows. A remote attacker can create a new account and overwrite the email address of an admin account to create unauthorized accounts and potentially take over accounts.
Account takeover is possible if a flow exists that allows email-verified password recovery.