๐Ÿ” CVE Alert

CVE-2026-94606

HIGH 8.9

authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage

CVSS Score
8.9
EPSS Score
0.0%
EPSS Percentile
0th

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a target user's password can substitute an attacker-controlled address, receive the one-time code, and finish enrolling the factor as the target. The target must not have enrolled the email factor already. Successful enrollment gives the actor a session as the target and access to single sign-on applications behind the account. Other authenticator types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.

CWE CWE-287 CWE-807
Vendor goauthentik
Product authentik
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for goauthentik authentik

Be the first to know when new high vulnerabilities affecting goauthentik authentik are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

goauthentik / authentik
< 2026.2.7 >= 2026.5.0, < 2026.5.7 >= 2026.8.0, < 2026.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/goauthentik/authentik/security/advisories/GHSA-qgqp-xh8r-v73r github.com: https://github.com/goauthentik/authentik/pull/25958 github.com: https://github.com/goauthentik/authentik/pull/25963 github.com: https://github.com/goauthentik/authentik/pull/25968 github.com: https://github.com/goauthentik/authentik/pull/25973 github.com: https://github.com/goauthentik/authentik/commit/01d4349f2aaa9beda532f92e2a251a17fefee9b3 github.com: https://github.com/goauthentik/authentik/commit/1fcf9868133e5d05e266edbc1f6f3ee972baa3f9 github.com: https://github.com/goauthentik/authentik/commit/c10ae83ebf8c61de2f1922edf1fab504d9f3b06f github.com: https://github.com/goauthentik/authentik/commit/ec41732339726fba477182c0906a8d930b145beb docs.goauthentik.io: https://docs.goauthentik.io/releases/2026.2#fixed-in-202627 docs.goauthentik.io: https://docs.goauthentik.io/releases/2026.5#fixed-in-202657 docs.goauthentik.io: https://docs.goauthentik.io/releases/2026.8#fixed-in-202682 github.com: https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7 github.com: https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7 github.com: https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2