critical · CVSS v3 8.8
CVE-2026-94609
authentik, an open-source identity provider, has a critical privilege escalation flaw. Accounts with delegated group or user management perm
Overview
authentik, an open-source identity provider, has a critical privilege escalation flaw. Accounts with delegated group or user management permissions can grant superuser status or assign roles without proper checks. This allows non-admin users to elevate privileges.
Description
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Impact
Confidentiality, Integrity, and Availability are at risk as attackers can gain superuser access, compromising all identities and services that rely on authentik. Defenders should be aware that any delegated group/user management accounts are vulnerable.
Remediation
Upgrade to version 2026.2.7 or later (2026.5.7/2026.8.2). If upgrading is not possible, revoke delegated permissions for group or user management or restrict those accounts to read‑only. Verify that group hierarchy checks and role assignment authorization are enforced.
Risk context
High urgency: critical severity and CVSS 8.8 indicate a severe privilege escalation that should be addressed promptly.
Affected products
- authentik
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —