Input validation error in authentik - CVE-2026-94613

 

Input validation error in authentik - CVE-2026-94613

Published: September 9, 2026 / Updated: September 28, 2026


Vulnerability identifier: #VU148584
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-94613
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of malformed SAML messages in the SAML message handling worker when processing specially formed SAML messages. A remote attacker can send a specially formed SAML message to cause a denial of service.

Only deployments using SAML in identity provider or source roles are affected. Worker processes are automatically restarted, and sessions survive because they are stored in the database.


Affected software

authentik

How to mitigate CVE-2026-94613

Install security update from vendor's website.

authentik - addressed in versions 2026.2.7, 2026.5.7, 2026.8.2

External References

Related Security Bulletins