Reliance on Untrusted Inputs in a Security Decision in authentik - CVE-2026-94606
Published: September 9, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass multi-factor authentication and sign in as another user.
The vulnerability exists due to reliance on untrusted input in a security decision in the email authenticator setup process when processing an authenticator setup request. A remote attacker can supply an email address they control and use the delivered one-time code to sign in as the target user.
Exploitation requires knowledge of the target user's password, an unenrolled email factor, and a deployment that enrolls the email authenticator during an authentication or enrollment flow.