Skip to main content

GHSA-cqj8-fxxf-9pg7

Reported by @0xWerz, @JebeenLee, @renmizo, @bhaswanthc, @vcth4nh, @bozellqp, @kanywst, @LoganCybersec, @gigioneggiando, @DavidCarliez

Authentication bypass in SAML Sources via assertion confusion and replay

Summary

A SAML Source accepted an assertion that its identity provider had issued for a different service provider, and it accepted the same assertion more than once. An actor who holds such an assertion could sign in as the user it names.

Patches

authentik 2026.2.7, 2026.5.7 and 2026.8.2 fix this issue.

Impact

Only deployments with a SAML Source are affected. SAML Providers and every other Source type are not affected.

The Source verified the signature and the validity period of an assertion. It did not verify that the identity provider had issued the assertion for the Source, or in answer to a login request from the Source. It kept no record of the assertions it had already accepted.

Workarounds

None. We recommend not relying on a SAML Source until you upgrade.

For more information

If you have any questions or comments about this advisory: