CVE-2026-72537
Received Received - Intake

Privilege Escalation in Authentik Security

Vulnerability report for CVE-2026-72537, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

Description

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. An attacker can rewrite or delete any account, including the superuser, using only a limited provisioning credential.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
authentik_security authentik to 2026.5.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a privilege escalation vulnerability in Authentik Security authentik through version 2026.5.6. An attacker with a source-scoped SCIM provisioning token can take over any user account, including superusers, by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts without validating scope boundaries, allowing the attacker to rewrite or delete any account.

Detection Guidance

Check for unauthorized SCIM provisioning activities or mismatched user accounts between SCIM and local authentik users. Review logs for SCIM token usage and account modifications. Look for provisioned users with admin privileges or changes to superuser accounts.

Impact Analysis

An attacker could gain full control over your Authentik instance, including admin accounts. This could lead to unauthorized access, data breaches, or complete system compromise. Even with limited provisioning credentials, an attacker can escalate privileges and manipulate accounts.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements and HIPAA's security rules. Organizations using affected versions may face compliance failures, legal penalties, and reputational damage due to compromised user accounts and potential data exposure.

Mitigation Strategies

Disable source-scoped SCIM provisioning tokens immediately. Audit all user accounts for unauthorized modifications or new accounts. Update authentik to the latest version beyond 2026.5.6. Restrict SCIM token scopes to prevent privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72537. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart