GHSA-cqj8-fxxf-9pg7
Reported by @0xWerz, @JebeenLee, @renmizo, @bhaswanthc, @vcth4nh, @bozellqp, @kanywst, @LoganCybersec, @gigioneggiando, @DavidCarliez
Authentication bypass in SAML Sources via assertion confusion and replay
Summary
A SAML Source accepted an assertion that its identity provider had issued for a different service provider, and it accepted the same assertion more than once. An actor who holds such an assertion could sign in as the user it names.
Patches
authentik 2026.2.7, 2026.5.7 and 2026.8.2 fix this issue.
Impact
Only deployments with a SAML Source are affected. SAML Providers and every other Source type are not affected.
The Source verified the signature and the validity period of an assertion. It did not verify that the identity provider had issued the assertion for the Source, or in answer to a login request from the Source. It kept no record of the assertions it had already accepted.
Workarounds
None. We recommend not relying on a SAML Source until you upgrade.
For more information
If you have any questions or comments about this advisory:
- Email us at [email protected]