CVE-2026-25227General(goauthentik / authentik)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch goauthentik authentik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the authentik server container through the test endpoint, which is intended to preview how a property mapping/policy works. authentik 2025.8.6, 2025.10.4, and 2025.12.4 fix this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authentik

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-02-13)
  • 5 total mentions across 2 days

Affected systems

Products
authentik

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-12: 2Mentions · 2026-02-13: 3Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-13: 2Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 202-1202-13
Signal classification3 categories
General
240.0%
Patch
240.0%
Disclosure
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-122
Disclosure1General1
2026-02-133
General1Patch2
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25227: CRITICAL] Critical security vulnerability found in authentik! Users with delegated permissions Can view * Property Mapping or Can view Expression Policy can execute arbitrary code. Update to...#cve,CVE-2026-25227,#cybersecurity https://cvefind.com/CVE-2026-25227

    Post summary

    A critical flaw in authentik permits arbitrary code execution for users with specific delegated permissions; an update to a patched version is advised.

    0101075
    583 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25227 Code Execution Vulnerability in authentik Identity Provider via D... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25227 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet cites CVE‑2026‑25227 for a code‑execution flaw in authentik Identity Provider but provides no technical details, PoC, exploitation evidence, or patch information.

    0001048
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25227 authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permi… https://www.cve.org/CVERecord?id=CVE-2026-25227

    Post summary

    The text references CVE-2026-25227 affecting certain authentik versions with a delegated permissions issue, but it offers no detailed technical description, exploit code, or patch information.

    00010171
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `goauthentik/authentik` is vulnerable to RCE (CVE-2026-25227) via context key injection in a test endpoint. Patching to the latest version is recommended. #authentik #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-25227-authentik-remote-code-execution

    Post summary

    CVE‑2026‑25227 causes remote code execution in authentik via context key injection; users should update to the latest version to remediate the issue.

    0000033
    1 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-25227 in goauthentik authentik enables code injection for users with specific permissions. Patch ASAP to prevent server compromise! 🔒 https://radar.offseq.com/threat/cve-2026-25227-cwe-94-improper-control-of-generati-cc39f642 #OffSeq #authentik #CodeInjection https://t.co/7xkgq2DZSx

    Post summary

    The tweet announces CVE‑2026‑25227, detailing a code injection vulnerability tied to specific user permissions, and urges an immediate patch to prevent potential server compromise. No evidence of active exploitation or a PoC is mentioned.

    0000047
    268 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgoauthentikauthentik---

Explore more