
CVE-2026-94609: Privilege escalation to superuser in @AuthentikSec , the open-source SSO platform with 25.9k GitHub stars. Superuser status is inherited through the group hierarchy, but the permission checks only looked at each group's own setting. A helpdesk account managing one group could promote itself to superuser. Patched in 2026.2.7, 2026.5.7, 2026.8.2. Found by a CyStack researcher. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #authentik #SSO #IAM #EnterpriseSecurity #InfoSec
