Skip to main content

GHSA-m9h4-7j9c-55x9

Reported by @0xWerz, @szybnev, @Santoshkumarpuppala, @gigioneggiando

Certain stored credentials readable with view permission alone

Summary

Several kinds of configuration store credentials. Reading such a configuration through the API returned those credentials, so view permission alone was enough to collect them.

Patches

authentik 2026.2.7, 2026.5.7 and 2026.8.2 fix this issue.

Impact

Affected: deployments that grant view permission on a configuration to accounts that are not meant to read the credentials it stores. Not affected: deployments where every account with view permission on such a configuration may already read those credentials.

This affects the configuration of one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications that authenticate with a client or shared secret, and applications that use a proxy provider.

Workarounds

Revoke view permissions from every user, role and group that does not need them.

For more information

If you have any questions or comments about this advisory: