Input validation error in authentik - CVE-2026-94613
Published: September 9, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of malformed SAML messages in the SAML message handling worker when processing specially formed SAML messages. A remote attacker can send a specially formed SAML message to cause a denial of service.
Only deployments using SAML in identity provider or source roles are affected. Worker processes are automatically restarted, and sessions survive because they are stored in the database.