Vulnerabilidades em goauthentik
36 resultadosAnálise Vexday
O goauthentik apresenta 36 CVEs catalogadas, com 9 publicações nos últimos 90 dias indicando atividade contínua de descoberta de vulnerabilidades. Embora nenhuma esteja sob ataque ativo no momento, 7 vulnerabilidades críticas (CVSS alto) centram-se em falhas de autenticação (CWE-287), o que é particularmente relevante dado o propósito da solução como plataforma de identidade.
CVE-2023-48228HIGHOAuth2: PKCE can be fully circumventedEPSS 1.2%CVE-2022-46145HIGHauthentik vulnerable to unauthorized user creation and potential account takeoverEPSS 1.2%CVE-2024-52289HIGHauthentik has an insecure default configuration for OAuth2 Redirect URIsEPSS 1.1%CVE-2022-23555CRITICALauthentik vulnerable to Improper Authentication via invitation URL token reuseEPSS 0.9%CVE-2026-25227CRITICALauthentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test EndpointEPSS 0.8%CVE-2023-36456HIGHAuthentik lacks Proxy IP headers validationEPSS 0.8%CVE-2024-37905HIGHImproper Access Control and Incorrect Authorization in github.com/goauthentik/authentikEPSS 0.8%CVE-2023-46249CRITICALauthentik potential installation takeover when default admin user is deletedEPSS 0.7%CVE-2026-25748HIGHauthentik has a forward authentication bypass with broken cookieEPSS 0.6%CVE-2024-38371HIGHInsufficient access control for OAuth2 Device Code flow in authentikEPSS 0.6%CVE-2024-47070CRITICALauthentik vulnerable to password authentication bypass via X-Forwarded-For HTTP headerEPSS 0.6%CVE-2024-42490HIGHauthentik has Insufficient Authorization for several API endpointsEPSS 0.6%CVE-2024-52287MEDIUMauthentik performs insufficient validation of OAuth scopesEPSS 0.6%CVE-2024-21637HIGHXSS in Authentik via JavaScript-URI as Redirect URI and form_post Response ModeEPSS 0.5%CVE-2024-23647MEDIUMPKCE downgrade attack in AuthentikEPSS 0.5%CVE-2022-46172MEDIUMauthentik allows existing authenticated users to create arbitrary accountsEPSS 0.5%CVE-2026-40172HIGHauthentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuserEPSS 0.5%CVE-2024-52307MEDIUMauthentik allows a timing attack due to missing constant time comparison for metrics viewEPSS 0.5%CVE-2023-39522MEDIUMUsername enumeration attack in goauthentikEPSS 0.5%CVE-2026-40165HIGHauthentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier TruncationEPSS 0.5%