28,678 Entries 2,229 Sources 5 Verticals Last sync 4 minutes Live
Self-hosted apps

authentik

Authentik
version/2025.12.6 bewährt latest release
28.05.2026

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

30 CVE(s) zuletzt, höchste Schwere: kritisch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
gh_etagW/"e6bea5532ce4dff8cb9cc203a1adbc15785eb060f9ca4edae3359e33f4bc9c10"
eol_productauthentik
gh_checked_at2026-06-08T02:00:46.648547+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps High

A security vulnerability in authentik's OAuth2 implementation allows attackers to bypass PKCE security checks by simply omitting the code_verifier parameter, even when the OAuth2 flow was initiated with a code_challenge.

CVE-2023-48228
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in Authentik software allows attackers to steal session tokens when OAuth2 providers are configured with wildcards (*) as allowed redirect URLs.

CVE-2024-21637
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in authentik's OAuth2 implementation allows attackers to bypass important PKCE security protections by removing certain parameters from authorization requests, enabling code injection attacks.

CVE-2024-23647
07.06.2026
CVE
Self-hosted apps High

A vulnerability in Authentik software allowed any logged-in user to grant themselves administrator privileges by manipulating API tokens and changing their user assignment.

CVE-2024-37905
07.06.2026
CVE
Self-hosted apps High

A security flaw in Authentik software bypasses access restrictions in OAuth2 Device Code Flow, allowing unauthorized users to obtain OAuth tokens and access protected applications.

CVE-2024-38371
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik software allows users to access certain API endpoints without proper authentication or authorization, potentially exposing sensitive certificate data.

CVE-2024-42490
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik allows applications and users to steal access tokens and use them to gain unauthorized access to other applications they shouldn't be able to access.

CVE-2024-47077
07.06.2026
CVE
Self-hosted apps Critical

A critical vulnerability in Authentik software allows attackers to bypass password authentication by sending a manipulated X-Forwarded-For HTTP header. This enables them to log into known user accounts without providing a password.

CVE-2024-47070
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Authentik software allowed attackers with valid OAuth credentials to obtain tokens with unconfigured permissions, which could then be misused for malicious actions in trusting systems.

CVE-2024-52287
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik's OAuth2 component allows attackers to bypass redirect URL validation by registering domains with similar names, potentially leading to unauthorized redirects.

CVE-2024-52289
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in authentik software allows attackers to guess the secret key used for authenticating an internal endpoint through repeated attempts. With this key, attackers can manipulate existing cookies or create new ones.

CVE-2024-52307
07.06.2026
CVE
Self-hosted apps High

A vulnerability in Authentik software causes deleted user sessions to not be properly revoked when using database storage, allowing users to maintain access even after session deletion.

CVE-2025-29928
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in authentik allows unauthorized users to access remote access connections by copying URLs with valid tokens, as session validation is missing.

CVE-2025-52553
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in authentik allows deactivated users with OAuth/SAML connections to partially access the system and authorize applications despite their accounts being disabled.

CVE-2025-53942
07.06.2026
CVE
Self-hosted apps Medium

In the authentik authentication software, deactivated service accounts for OAuth providers can still be used for login even though they should be blocked.

CVE-2025-64521
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the authentik authentication software allows users to use expired invitations because they are not immediately recognized as invalid.

CVE-2025-64708
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik allows attackers to bypass authentication by using malformed cookies when authentik is configured as a Proxy Provider with Traefik or Caddy reverse proxies.

CVE-2026-25748
07.06.2026
CVE
Self-hosted apps Critical

A vulnerability in authentik allows users with certain view permissions to execute arbitrary code on the server and thereby gain complete control over the application.

CVE-2026-25227
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik allows attackers to authenticate as any existing user by injecting malicious SAML assertions before valid signed assertions when certain security settings are not properly configured.

CVE-2026-25922
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik software allows users with limited management permissions to elevate themselves or other users to administrators with full system privileges by bypassing security controls.

CVE-2026-40172
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik allows attackers to poison OAuth2 providers by permanently storing malicious redirect URLs before authentication occurs. This leads to authorization code interception and potential account takeover for all subsequent OAuth2 login flows using the affected provider.

Advisory
07.06.2026
CVE
Self-hosted apps Medium

A security flaw in authentik's SAML processing ignores time limits and audience restrictions in authentication tokens, allowing attackers to reuse expired tokens or tokens intended for other services.

CVE-2026-41577
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik allows authenticated non-admin users to retrieve secret OAuth2 client credentials from providers they previously authenticated against, potentially enabling unauthorized reuse of these confidential authentication credentials.

CVE-2026-40166
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik allows attackers to bypass nginx authentication by setting a specific HTTP header, enabling unauthorized access to protected applications without any login credentials.

Advisory
07.06.2026
CVE
Self-hosted apps High

A vulnerability in Authentik software allows attackers to gain access to other user accounts by manipulating SAML assertions through injecting XML comments into NameID values.

CVE-2026-40165
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in authentik's WS-Federation provider allows attackers to redirect users to malicious websites where they can intercept valid login credentials that can be misused for identity impersonation.

CVE-2026-41569
07.06.2026
CVE
Self-hosted apps Critical

A critical vulnerability in authentik's Simple Flow Executor allows cross-site scripting attacks, enabling attackers to hijack user sessions or redirect users to malicious sites.

CVE-2026-42849
07.06.2026
CVE
Self-hosted apps High

A security flaw in authentik's SAML authentication allows attackers to impersonate other users by manipulating valid digital signatures and injecting forged identity data.

CVE-2026-47201
07.06.2026
CVE
Self-hosted apps High

A vulnerability in authentik allows attackers with low privileges to log in as any user by manipulating connections between user accounts and external sources.

CVE-2026-49443
07.06.2026
CVE
Self-hosted apps Critical

A critical security vulnerability in Authentik software allows attackers to bypass authentication stages by sending an empty POST request, enabling them to log in without providing valid credentials.

CVE-2026-49448
07.06.2026
REL
Self-hosted apps bewährt

Release 2026-05-28

version/2025.12.6
28.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-28

version/2026.2.4
28.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-28

version/2026.5.2
28.05.2026
EOL
Self-hosted apps

Current / stable

2026.5
22.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-22

version/2026.5.0
22.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-13

version/2026.5.0-rc2
13.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-12

version/2025.12.5
12.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-12

version/2026.2.3
12.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-11

version/2026.5.0-rc1
11.05.2026
REL
Self-hosted apps bewährt

Release 2026-04-10

version/2026.2.3-rc1
10.04.2026
REL
Self-hosted apps bewährt

Release 2026-04-07

version/2026.2.2-rc3
07.04.2026
REL
Self-hosted apps bewährt

Release 2026-04-07

version/2026.2.2
07.04.2026
REL
Self-hosted apps bewährt

Release 2026-04-02

version/2026.2.2-rc2
02.04.2026
REL
Self-hosted apps bewährt

Release 2026-04-01

version/2026.2.2-rc1
01.04.2026
REL
Self-hosted apps bewährt

Release 2026-03-03

version/2026.2.1
03.03.2026
REL
Self-hosted apps bewährt

Release 2026-03-02

version/2026.2.1-rc1
02.03.2026
EOL
Self-hosted apps

Current / stable

2026.2
24.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-24

version/2026.2.0-rc5
24.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-24

version/2026.2.0
24.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-17

version/2026.2.0-rc4
17.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-16

version/2026.2.0-rc3
16.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-12

version/2026.2.0-rc2
12.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-12

version/2025.10.4
12.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-12

version/2025.12.4
12.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-12

version/2025.8.6
12.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-11

version/2026.2.0-rc1
11.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-02

version/2025.12.3
02.02.2026
REL
Self-hosted apps bewährt

Release 2026-01-30

version/2025.12.2
30.01.2026
REL
Self-hosted apps bewährt

Release 2026-01-16

version/2025.12.1
16.01.2026
EOL
Self-hosted apps

EOL 2026-05-22

2025.12
13.01.2026
REL
Self-hosted apps bewährt

Release 2026-01-13

version/2025.12.0
13.01.2026
REL
Self-hosted apps bewährt

Release 2026-01-06

version/2025.12.0-rc3
06.01.2026
REL
Self-hosted apps bewährt

Release 2025-12-17

version/2025.12.0-rc2
17.12.2025
EOL
Self-hosted apps

EOL 2026-02-24

2025.10
27.10.2025
EOL
Self-hosted apps

EOL 2026-01-13

2025.8
20.08.2025
EOL
Self-hosted apps

EOL 2025-10-27

2025.6
03.06.2025
EOL
Self-hosted apps

EOL 2025-08-20

2025.4
29.04.2025
EOL
Self-hosted apps

EOL 2025-04-30

2024.12
19.12.2024
EOL
Self-hosted apps

EOL 2024-04-24

2023.10
26.10.2023
EOL
Self-hosted apps

EOL 2023-02-14

2022.12
28.12.2022
EOL
Self-hosted apps

EOL 2022-02-16

2021.12
16.12.2021