Improper Authentication in authentik - CVE-2026-25748
Published: April 23, 2026
authentik
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication and gain access to the application.
The vulnerability exists due to improper authentication in the Proxy Provider forward authentication handling when processing a malformed session cookie behind Traefik or Caddy. A remote attacker can send a malformed session cookie to bypass authentication and gain access to the application.
Exploitation depends on the behavior of applications behind the Proxy Provider, particularly whether they require an X-Authentik header to be present.