CVE-2026-94609

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Referenced assets1 URL
By indicator
Full discourse1 post
  • CyStack@CyStackSecurity

    CVE-2026-94609: Privilege escalation to superuser in @AuthentikSec , the open-source SSO platform with 25.9k GitHub stars. Superuser status is inherited through the group hierarchy, but the permission checks only looked at each group's own setting. A helpdesk account managing one group could promote itself to superuser. Patched in 2026.2.7, 2026.5.7, 2026.8.2. Found by a CyStack researcher. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #authentik #SSO #IAM #EnterpriseSecurity #InfoSec

    10030158
    3.7K followersView on X

Explore more