authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue has been patched in versions 2025.12.5, 2026.2.3, and 2026.5.1.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c3m2-jqmq-pvp3 | authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 03 Jun 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goauthentik
Goauthentik authentik |
|
| Vendors & Products |
Goauthentik
Goauthentik authentik |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue has been patched in versions 2025.12.5, 2026.2.3, and 2026.5.1. | |
| Title | authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T20:30:55.674Z
Reserved: 2026-05-18T22:07:37.436Z
Link: CVE-2026-47201
No data.
Status : Received
Published: 2026-06-02T21:16:27.940
Modified: 2026-06-02T21:16:27.940
Link: CVE-2026-47201
No data.
OpenCVE Enrichment
Updated: 2026-06-03T04:30:05Z
Weaknesses
Github GHSA