GHSA-m9h4-7j9c-55x9
Reported by @0xWerz, @szybnev, @Santoshkumarpuppala, @gigioneggiando
Certain stored credentials readable with view permission alone
Summary
Several kinds of configuration store credentials. Reading such a configuration through the API returned those credentials, so view permission alone was enough to collect them.
Patches
authentik 2026.2.7, 2026.5.7 and 2026.8.2 fix this issue.
Impact
Affected: deployments that grant view permission on a configuration to accounts that are not meant to read the credentials it stores. Not affected: deployments where every account with view permission on such a configuration may already read those credentials.
This affects the configuration of one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications that authenticate with a client or shared secret, and applications that use a proxy provider.
Workarounds
Revoke view permissions from every user, role and group that does not need them.
For more information
If you have any questions or comments about this advisory:
- Email us at [email protected]