rootpwn

critical · CVSS v3 8.8

CVE-2026-94609

authentik, an open-source identity provider, has a critical privilege escalation flaw. Accounts with delegated group or user management perm

Overview

authentik, an open-source identity provider, has a critical privilege escalation flaw. Accounts with delegated group or user management permissions can grant superuser status or assign roles without proper checks. This allows non-admin users to elevate privileges.

Description

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.

Impact

Confidentiality, Integrity, and Availability are at risk as attackers can gain superuser access, compromising all identities and services that rely on authentik. Defenders should be aware that any delegated group/user management accounts are vulnerable.

Remediation

Upgrade to version 2026.2.7 or later (2026.5.7/2026.8.2). If upgrading is not possible, revoke delegated permissions for group or user management or restrict those accounts to read‑only. Verify that group hierarchy checks and role assignment authorization are enforced.

Risk context

High urgency: critical severity and CVSS 8.8 indicate a severe privilege escalation that should be addressed promptly.

Affected products

  • authentik

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
—
EPSS
—

authentik privilege-escalation identity-provider critical group-management role-assignment patch

← All CVEs