CVE-2026-94613
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or /source/saml/*, causing the requests assigned to that worker to fail. Worker process termination and automatic restart do not destroy database-backed sessions, but continued malicious messages can cause a sustained share of legitimate traffic to fail. Other protocol implementations are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
770
Allocation of Resources Without Limits or Throttling
IncompleteCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Dos: Resource Consumption (Other)
Applicable Platforms
All platforms may be affected
https://docs.goauthentik.io/releases/2026.2#fixed-in-202627
https://docs.goauthentik.io/releases/2026.5#fixed-in-202657
https://docs.goauthentik.io/releases/2026.8#fixed-in-202682
https://github.com/goauthentik/authentik/commit/03d19d63b8d8dd7bc3de7cf6e57c6df…
https://github.com/goauthentik/authentik/commit/4cf2f803b1c2ef38c224eead375fd05…
https://github.com/goauthentik/authentik/commit/732adad26bb97361b6bf25ef138df5c…
https://github.com/goauthentik/authentik/commit/a029f5372295bfeb1e334855f786016…
https://github.com/goauthentik/authentik/pull/25959
https://github.com/goauthentik/authentik/pull/25964
https://github.com/goauthentik/authentik/pull/25969
https://github.com/goauthentik/authentik/pull/25974
https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7
https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2
https://github.com/goauthentik/authentik/security/advisories/GHSA-cxwx-9x59-28qm