Vulnerabilities in goauthentik

45 results
Vexday analysis

O goauthentik apresenta 36 CVEs catalogadas, com 9 publicações nos últimos 90 dias indicando atividade contínua de descoberta de vulnerabilidades. Embora nenhuma esteja sob ataque ativo no momento, 7 vulnerabilidades críticas (CVSS alto) centram-se em falhas de autenticação (CWE-287), o que é particularmente relevante dado o propósito da solução como plataforma de identidade.

CVE-2024-52307MEDIUMauthentik allows a timing attack due to missing constant time comparison for metrics viewEPSS 0.6%CVE-2024-21637HIGHXSS in Authentik via JavaScript-URI as Redirect URI and form_post Response ModeEPSS 0.5%CVE-2024-23647MEDIUMPKCE downgrade attack in AuthentikEPSS 0.5%CVE-2022-46172MEDIUMauthentik allows existing authenticated users to create arbitrary accountsEPSS 0.5%CVE-2025-53942HIGHauthentik has an insufficient check for account active status during OAuth/SAML authenticationEPSS 0.5%CVE-2025-52553MEDIUMauthentik has Insufficient Session verification for Remote Access Control endpoint accessEPSS 0.5%CVE-2024-42490HIGHauthentik has Insufficient Authorization for several API endpointsEPSS 0.5%CVE-2026-42849CRITICALauthentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeoverEPSS 0.5%CVE-2026-49443HIGHauthentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the APIEPSS 0.4%CVE-2026-55106MEDIUMauthentik: Unauthenticated LDAP directory data disclosureEPSS 0.4%CVE-2024-47077MEDIUMauthentik cross-provider token validation problemsEPSS 0.4%CVE-2025-29928HIGHauthentik's deletion of sessions did not revoke sessions when using database session storageEPSS 0.4%CVE-2026-41569MEDIUMauthentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpointsEPSS 0.3%CVE-2026-25922HIGHauthentik has a Signature Verification Bypass via SAML Assertion WrappingEPSS 0.3%CVE-2024-11623MEDIUMStored XSS in authentikEPSS 0.3%CVE-2026-47201HIGHauthentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated userEPSS 0.3%CVE-2023-26481CRITICALInsufficient user check in FlowTokens by Email stageEPSS 0.3%CVE-2025-64708MEDIUMauthentik invitation expiry is delayed by at least 5 minutesEPSS 0.2%CVE-2025-64521MEDIUMauthentik deactivated service accounts can authenticate to OAuthEPSS 0.2%CVE-2026-41577MEDIUMauthentik: SAML source does not validate Conditions, timing, or audience on assertionsEPSS 0.2%