Authorization bypass through user-controlled key in authentik - CVE-2026-61574

 

Authorization bypass through user-controlled key in authentik - CVE-2026-61574

Published: July 17, 2026


Vulnerability identifier: #VU138384
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-61574
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through user-controlled key in the RAC endpoint list endpoint when handling requests for configured endpoints. A remote user can request the endpoint list to disclose sensitive information.

Only deployments using the enterprise Remote Access Control provider are affected, and credential exposure occurs when connection credentials are stored for endpoints.


Affected software

authentik

How to mitigate CVE-2026-61574

Install security update from vendor's website.

authentik - addressed in versions 2026.2.6, 2026.5.5

External References

Related Security Bulletins