CVE-2026-25922Patch(goauthentik / authentik)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch goauthentik authentik systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificate setting under Advanced Protocol settings configured, it was possible for an attacker to inject a malicious assertion before the signed assertion that authentik would use instead. authentik 2025.8.6, 2025.10.4, and 2025.12.4 fix this issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authentik

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-12); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
authentik

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-02-12: 2Mentions · 2026-02-13: 2PoC Mentioned / Linked · 2026-02-13: 1Patch / Workaround · 2026-02-12: 2Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 202-1202-13
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-122
Patch2
2026-02-132
Disclosure2
Full discourse4 posts
  • CVE@CVEnew
    Patch

    CVE-2026-25922 authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature un… https://www.cve.org/CVERecord?id=CVE-2026-25922

    Post summary

    CVE-2026-25922 is a SAML assertion signature verification flaw in authentik; versions before 2025.8.6, 2025.10.4, and 2025.12.4 contain the patch.

    00010132
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A Signature Verification Bypass (CVE-2026-25922) affects `goauthentik/authentik` via SAML assertion wrapping, potentially leading to unauthorized access. #authentik #SAML #infosec https://www.pulsepatch.io/posts/cve-2026-25922-authentik-saml-bypass

    Post summary

    The post announces CVE‑2026‑25922, a signature verification bypass in the authentik SAML implementation that could allow unauthorized access, and links to a PulsePatch article for details.

    0000028
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25922 SAML Assertion Injection Vulnerability in authentik Identity Provider https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25922

    Post summary

    A new CVE (CVE-2026-25922) describing a SAML assertion injection flaw in authentik Identity Provider has been announced, but no PoC, exploit code, or patch details are provided.

    0000033
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25922: HIGH] Critical security update! Ensure your authentik identity provider is updated to versions 2025.8.6, 2025.10.4, or 2025.12.4 to prevent malicious assertion injection vulnerabilities. #cy...#cve,CVE-2026-25922,#cybersecurity https://cvefind.com/CVE-2026-25922

    Post summary

    The post announces the high‑severity CVE‑2026‑25922 and directs users to update authentik to specific patched versions to mitigate an assertion injection vulnerability.

    0000045
    583 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgoauthentikauthentik---

Explore more