Vulnerabilidades em goauthentik

36 resultados
Análise Vexday

O goauthentik apresenta 36 CVEs catalogadas, com 9 publicações nos últimos 90 dias indicando atividade contínua de descoberta de vulnerabilidades. Embora nenhuma esteja sob ataque ativo no momento, 7 vulnerabilidades críticas (CVSS alto) centram-se em falhas de autenticação (CWE-287), o que é particularmente relevante dado o propósito da solução como plataforma de identidade.

CVE-2025-53942HIGHauthentik has an insufficient check for account active status during OAuth/SAML authenticationEPSS 0.5%CVE-2026-40166HIGHauthentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/EPSS 0.5%CVE-2025-52553MEDIUMauthentik has Insufficient Session verification for Remote Access Control endpoint accessEPSS 0.4%CVE-2024-47077MEDIUMauthentik cross-provider token validation problemsEPSS 0.4%CVE-2026-49448CRITICALauthentik: SourceStage bypass via empty POSTEPSS 0.4%CVE-2025-29928HIGHauthentik's deletion of sessions did not revoke sessions when using database session storageEPSS 0.4%CVE-2026-42849CRITICALauthentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeoverEPSS 0.4%CVE-2026-49443HIGHauthentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the APIEPSS 0.3%CVE-2024-11623MEDIUMStored XSS in authentikEPSS 0.3%CVE-2023-26481CRITICALInsufficient user check in FlowTokens by Email stageEPSS 0.3%CVE-2025-64708MEDIUMauthentik invitation expiry is delayed by at least 5 minutesEPSS 0.2%CVE-2026-25922HIGHauthentik has a Signature Verification Bypass via SAML Assertion WrappingEPSS 0.2%CVE-2025-64521MEDIUMauthentik deactivated service accounts can authenticate to OAuthEPSS 0.2%CVE-2026-41569MEDIUMauthentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpointsEPSS 0.2%CVE-2026-47201HIGHauthentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated userEPSS 0.2%CVE-2026-41577MEDIUMauthentik: SAML source does not validate Conditions, timing, or audience on assertionsEPSS 0.2%