CVE-2022-46145 is a critical vulnerability affecting authentik versions prior to 2022.11.2 and 2022.10.2, an open-source identity provider. It allows unauthenticated users to create new accounts and, if specific flows are enabled, potentially take over administrator accounts by overwriting their email addresses. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low complexity, and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022.10.2CPE matchmatch criteria | cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:* | ||
>= 2022.11, < 2022.11.2CPE matchmatch criteria | cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.