CVE-2026-25748Disclosure(goauthentik / authentik)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch goauthentik authentik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. When a malicious cookie was used, none of the authentik-specific X-Authentik-* headers were set which depending on application can grant access to an attacker. authentik 2025.10.4 and 2025.12.4 fix this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authentik

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
authentik

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-12: 2Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-14: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 102-1202-1302-14
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-122
Disclosure2
2026-02-131
Disclosure1
2026-02-141
Patch1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25748 Authentication Bypass in authentik Proxy Provider with Malformed Cookies https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25748

    Post summary

    The text announces CVE‑2026‑25748, detailing an authentication bypass in authentik Proxy Provider caused by malformed cookies, but provides no evidence of PoC, exploit, or mitigation.

    0001141
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25748: HIGH] Authentik identity provider had a security vulnerability allowing authentication bypass with malicious cookies when integrated with Traefik or Caddy as reverse proxy. Fixed in versions...#cve,CVE-2026-25748,#cybersecurity https://cvefind.com/CVE-2026-25748

    Post summary

    The post discloses a high‑severity authentication bypass vulnerability in Authentik when used with Traefik or Caddy reverse proxies, notes that a fix exists, and provides a link to the CVE record.

    0001052
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25748 authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward a… https://www.cve.org/CVERecord?id=CVE-2026-25748

    Post summary

    CVE‑2026‑25748 enables authentication bypass in authentik via a malformed cookie; the issue was mitigated in releases 2025.10.4 and 2025.12.4.

    00010148
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Authentik` users should note a forward authentication bypass (CVE-2026-25748) due to a broken cookie mechanism. Update to patched versions to prevent unauthorized access. #Authentik #AuthBypass #InfoSec https://www.pulsepatch.io/posts/cve-2026-25748-authentik-auth-bypass

    Post summary

    Authentik users are warned of an authentication bypass vulnerability (CVE-2026-25748) caused by a broken cookie mechanism; updating to patched versions is advised to prevent unauthorized access.

    0000027
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgoauthentikauthentik---

Explore more