Authentik

Vendor:

First CVE: Dec 2, 2022 · Active for 3 years

33
Total CVEs
More Total CVEs than 96% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Authentik over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 2022
3 years ago
Most Recent CVE
Jun 2, 2026
54 days ago

CVE Severity & Scoring

Authentik33 CVEs
All CVEs352,713 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (81.8%)
High6 (18.2%)
Unknown0 (0.0%)
User Interaction
None23 (69.7%)
Unknown0 (0.0%)
Required10 (30.3%)
Privileges Required
Low7 (21.2%)
High4 (12.1%)
None22 (66.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been p
Jun 2, 20269.841NONO
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the
Jun 2, 20269.338NONO
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in on
Jun 2, 20268.837NONO
authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping whe
Jun 2, 20268.535NONO
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the defau
Dec 2, 20229.831NONO
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Condit
Jun 2, 20267.530NONO
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authen
Nov 21, 20239.830NONO
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verificati
Feb 12, 20268.829NONO
authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reu
Dec 28, 20228.829NONO
authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check ra
Jun 2, 20266.127NONO

Exploit Exposure

Signals from CVEs in this product scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (33 CVEs).

Media Mentions

Signals from CVEs in this product scope (33 CVEs).

Top CNAs Publishing CVEs For Authentik

Top CWEs

Versions

No cataloged versions.