CVE-2026-94612
Received Received - Intake

SAML Assertion Replay in authentik Identity Provider

Vulnerability report for CVE-2026-94612, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: GitHub, Inc.

Description

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML Source also does not record already accepted assertions, allowing replay. An unauthenticated actor who possesses such a valid assertion can use an assertion intended for another service provider or reuse an earlier assertion to authenticate as the user named by the assertion. Only SAML Sources are affected; SAML Providers and other Source types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
goauthentik authentik 2026.2.7
goauthentik authentik 2026.5.7
goauthentik authentik 2026.8.2
goauthentik authentik to 2026.2.7 (exc)
goauthentik authentik to 2026.5.7 (exc)
goauthentik authentik to 2026.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects authentik's SAML Source functionality. It allows an unauthenticated actor to use a valid SAML assertion intended for another service provider or reuse an earlier assertion to authenticate as a user. The issue occurs because the system verifies the assertion's signature and validity period but does not check if the assertion was issued for that specific Source or in response to a login request from it. Additionally, the system does not track already accepted assertions, enabling replay attacks.

Impact Analysis

If you use authentik with SAML Sources, an attacker could impersonate legitimate users by replaying stolen or intercepted SAML assertions. This could lead to unauthorized access to sensitive data or systems protected by authentik. The impact includes potential data breaches, unauthorized actions performed on behalf of users, and loss of trust in the identity provider.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other regulations that require strong authentication and protection of user data. Unauthorized access due to this flaw may result in data breaches, violating privacy and security requirements. Organizations using affected versions may face legal penalties, reputational damage, and loss of certification.

Mitigation Strategies

Update authentik to versions 2026.2.7, 2026.5.7, or 2026.8.2 or later to address the SAML assertion validation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94612. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart