Skip to main content

GHSA-qgqp-xh8r-v73r

Reported by @CallumBasham, @MattWidz

MFA bypass via recipient override in the email authenticator

Summary

An actor who knows a user's password could have the one-time code for the email based multi-factor authenticator delivered to an address they control, and then finish signing in as that user.

Patches

authentik 2026.2.7, 2026.5.7 and 2026.8.2 fix this issue.

Impact

Only deployments that enroll the email authenticator during an authentication or enrollment flow are affected. Other authenticator types are not affected.

During setup of the authenticator, the address that received the code was taken from the setup request instead of the address the flow had already established.

The target must not have enrolled the factor yet. Completing the factor gives the actor a session as that user, and access to any single sign-on application behind the account.

Workarounds

None. We recommend not relying on the email authenticator for multi-factor authentication until upgrading.

For more information

If you have any questions or comments about this advisory: