Input validation error in authentik - CVE-2026-41569
Published: May 12, 2026
authentik
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive authentication information.
The vulnerability exists due to improper input validation in the WS-Federation provider when processing a user-supplied wreply parameter. A remote attacker can craft a login link with an attacker-controlled wreply value to disclose sensitive authentication information.
Only WS-Federation providers with a prefix-ambiguous Reply URL are affected, and the victim's browser must follow the crafted login link.