CVE-2026-94613 Details
Description
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or /source/saml/*, causing the requests assigned to that worker to fail. Worker process termination and automatic restart do not destroy database-backed sessions, but continued malicious messages can cause a sustained share of legitimate traffic to fail. Other protocol implementations are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
A denial-of-service vulnerability has been identified in authentik, an open-source identity provider, affecting versions prior to 2026.2.7, 2026.5.7, and 2026.8.2. The issue arises when an unauthenticated attacker sends a malformed SAML message to an authentik deployment using SAML in either the identity-provider or source role. This malformed message can disrupt the worker process handling SAML requests, causing a failure in those requests. Although the worker process is automatically restarted, the disruption can lead to a significant portion of legitimate traffic failing. The vulnerability is not present in other protocol implementations.
To address this vulnerability, users can upgrade to authentik versions 2026.2.7, 2026.5.7, or 2026.8.2. If an immediate upgrade is not possible, requests to the SAML endpoints can be blocked at the reverse proxy or load balancer level as a temporary workaround.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| authentik | <= 2026.8.1 (semver) <= 2026.5.6 (semver) <= 2026.2.6 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion