Code Injection in authentik - CVE-2026-25227

 

Code Injection in authentik - CVE-2026-25227

Published: April 23, 2026


Vulnerability identifier: #VU127148
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25227
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the policy/property mapping test endpoint when handling test requests for expression policies or property mappings. A remote privileged user can send a specially crafted request to execute arbitrary code.

Exploitation requires delegated permissions that grant the ability to view property mappings or expression policies, and the executed code can access the entire authentik database and environment variables.


Affected software

authentik

How to mitigate CVE-2026-25227

Install security update from vendor's website.

authentik - addressed in versions 2025.8.6, 2025.10.4, 2025.12.4

External References

Related Security Bulletins