Improper access control in authentik - #VU131248
Published: May 12, 2026
authentik
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication and access protected backend resources.
The vulnerability exists due to improper access control in the authentik outpost nginx forward-auth integration when processing a client-controlled X-Original-URI header. A remote attacker can send a specially crafted HTTP request with an injected X-Original-URI header to bypass authentication and access protected backend resources.
Only deployments using authentik's nginx forward-auth integration are affected; Traefik, Caddy, and proxy mode deployments are not affected.