Incorrect authorization in authentik - CVE-2026-94609
Published: September 9, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to incorrect authorization in delegated group and user management when managing delegated groups or users. A remote user can grant superuser status to an account or assign an existing role to a group to escalate privileges.
Only deployments that delegate group, group membership, or user management to non-administrator accounts are affected.