Authentik
Vendor:
First CVE: Dec 2, 2022 · Active for 3 years
33
Total CVEs
More Total CVEs than 96% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Authentik over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 2022
3 years ago
Most Recent CVE
Jun 2, 2026
54 days ago
CVE Severity & Scoring
Authentik33 CVEs
30%
42%
27%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (81.8%)
High6 (18.2%)
Unknown0 (0.0%)
User Interaction
None23 (69.7%)
Unknown0 (0.0%)
Required10 (30.3%)
Privileges Required
Low7 (21.2%)
High4 (12.1%)
None22 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49448CRITICAL authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been p | Jun 2, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-42849CRITICAL authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the | Jun 2, 2026 | 9.3 | 38 | NO | NO |
CVE-2026-49443HIGH authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in on | Jun 2, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-47201HIGH authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping whe | Jun 2, 2026 | 8.5 | 35 | NO | NO |
CVE-2022-46145CRITICAL authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the defau | Dec 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-41577HIGH authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Condit | Jun 2, 2026 | 7.5 | 30 | NO | NO |
CVE-2023-48228CRITICAL authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authen | Nov 21, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-25922HIGH authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verificati | Feb 12, 2026 | 8.8 | 29 | NO | NO |
CVE-2022-23555HIGH authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reu | Dec 28, 2022 | 8.8 | 29 | NO | NO |
CVE-2026-41569MEDIUM authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check ra | Jun 2, 2026 | 6.1 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Authentik
Top CWEs
Versions
No cataloged versions.