Improper Verification of Cryptographic Signature in authentik - CVE-2026-47201
Published: May 29, 2026
authentik
Detailed vulnerability description
The vulnerability allows a remote user to authenticate as another federated user.
The vulnerability exists due to xml signature wrapping in SAML Source ACS endpoint when validating upstream SAML responses. A remote user can submit a crafted SAML response containing a forged assertion while reusing a valid signed assertion to authenticate as another federated user.
The issue affects deployments using a SAML Source for upstream SAML federation with signed assertions, or signed responses without signed assertions.