Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. authentik/
  3. authentik

authentik

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 19 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Open-source identity provider with SSO, MFA, and application proxy capabilities

by authentik · goauthentik.io · source ↗

Known CVEs (19)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-29928 ↗HIGH 8.02025

    authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deletin…

  • CVE-2024-11623 ↗MEDIUM 4.82025

    Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons.  This action could only be performed by an authenticated admin user. The i…

  • CVE-2024-52307 ↗MEDIUM 5.62024

    authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the SECRET_KEY, which is used to authentic…

  • CVE-2024-52289 ↗CRITICAL 9.82024

    authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will aut…

  • CVE-2024-52287 ↗HIGH 7.22024

    authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't bee…

  • CVE-2024-47077 ↗MEDIUM 6.52024

    authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user again…

  • CVE-2024-47070 ↗CRITICAL 9.02024

    authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsabl…

  • CVE-2024-42490 ↗HIGH 7.52024

    authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/c…

  • CVE-2024-38371 ↗HIGH 8.62024

    authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the co…

  • CVE-2024-37905 ↗HIGH 8.82024

    authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of …

  • CVE-2024-23647 ↗MEDIUM 6.52024

    Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge paramete…

  • CVE-2024-21637 ↗HIGH 7.62024

    Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. T…

  • CVE-2023-48228 ↗HIGH 7.52023

    authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if t…

  • CVE-2023-46249 ↗CRITICAL 9.62023

    authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of…

  • CVE-2023-36456 ↗HIGH 8.32023

    authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and t…

  • CVE-2023-26481 ↗CRITICAL 9.12023

    authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for…

  • CVE-2022-46172 ↗MEDIUM 6.42022

    authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts t…

  • CVE-2022-23555 ↗CRITICAL 9.42022

    authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URL…

  • CVE-2022-46145 ↗HIGH 8.12022

    authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenti…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Identity & Access Management products

see all →
  • 1Password Extended Access Management · 1Password
  • AD Guardian Cloud · CionSystems
  • ARCON Privileged Access Management · ARCON
  • Abbey Labs · Abbey Labs
  • Aceiss · Aceiss
  • Active Directory Permissions Analyzer · Paramount Defenses
  • Adaptive MFA · Okta
  • Adaxes · softerra adaxes