CVE-2026-54730
Received Received - Intake

Authentication Bypass in Authentik via Chrome Device Trust

Vulnerability report for CVE-2026-54730, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: GitHub, Inc.

Description

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage in an authentication flow. The device attestation occurs in a verification iframe that calls the Google Verified Access API and records the verified device on success, but the vulnerable stages treat the flow as passed as soon as the stage is submitted. An attacker who can reach such a stage, including after primary username and password authentication, can skip the verification iframe and authenticate from a device that was never verified. Where device trust is the only additional factor, that protection is fully bypassed, while other configured factors remain in force. This issue is fixed in versions 2026.2.6 and 2026.5.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-09-08
AI Q&A
2026-08-18
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
google chrome to 2026.2.6 (inc)
google chrome to 2026.5.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-807 The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in authentik versions before 2026.2.6 and 2026.5.5 allows attackers to bypass device verification in authentication flows. The Google Chrome device-trust stages advance the flow without confirming that the device attestation actually ran. This means an attacker can skip the verification step and authenticate from an unverified device.

Detection Guidance

Check authentik versions for affected stages. Run commands like 'authentik version' or inspect logs for Google Chrome Endpoint stage in REQUIRED mode or deprecated Google Chrome Device Trust Connector stage usage.

Impact Analysis

If you use authentik with Google Chrome device-trust stages set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage, attackers could bypass device verification. This could allow unauthorized access to systems even when device trust is required as an additional factor.

Compliance Impact

This vulnerability allows attackers to bypass device verification, potentially granting unauthorized access to systems. For GDPR, this could lead to unauthorized data access, violating principles of data protection and user consent. Under HIPAA, it may result in unauthorized access to protected health information, compromising confidentiality requirements.

Mitigation Strategies

Upgrade authentik to versions 2026.2.6 or 2026.5.5 or later. Remove or disable the Google Chrome Endpoint stage in REQUIRED mode and the deprecated Google Chrome Device Trust Connector stage from authentication flows.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54730. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart