CVE-2026-94609 Details
Description
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
A vulnerability in authentik, an open-source identity provider, allows accounts with delegated permissions to manage groups, memberships, or users to grant superuser status or assign roles to groups without the necessary authorization. This issue affects versions prior to 2026.2.7, 2026.5.7, and 2026.8.2, and only impacts deployments that delegate these management capabilities to non-administrator accounts. The vulnerability arises from inconsistent group hierarchy checks and a lack of authorization for role assignments.
Users can upgrade to authentik versions 2026.2.7, 2026.5.7, or 2026.8.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| authentik | < 2026.2.7 (semver) < 2026.5.7 (semver) < 2026.8.2 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion