Improper access control in authentik - CVE-2026-54730

 

Improper access control in authentik - CVE-2026-54730

Published: July 17, 2026


Vulnerability identifier: #VU138385
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54730
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass device-trust verification and authenticate from an unverified device.

The vulnerability exists due to improper access control in the Google Chrome device-trust stages when advancing the authentication flow. A remote user can submit the stage without completing device attestation to bypass device-trust verification and authenticate from an unverified device.

Exploitation requires access to an authentication flow that uses either an Endpoint stage backed by a Google Chrome connector set to required mode or the deprecated Google Chrome Device Trust Connector stage. Other authentication factors, if configured, remain in force.


Affected software

authentik

How to mitigate CVE-2026-54730

Install security update from vendor's website.

authentik - addressed in versions 2026.2.6, 2026.5.5

External References

Related Security Bulletins