GHSA-qgqp-xh8r-v73r
Reported by @CallumBasham, @MattWidz
MFA bypass via recipient override in the email authenticator
Summary
An actor who knows a user's password could have the one-time code for the email based multi-factor authenticator delivered to an address they control, and then finish signing in as that user.
Patches
authentik 2026.2.7, 2026.5.7 and 2026.8.2 fix this issue.
Impact
Only deployments that enroll the email authenticator during an authentication or enrollment flow are affected. Other authenticator types are not affected.
During setup of the authenticator, the address that received the code was taken from the setup request instead of the address the flow had already established.
The target must not have enrolled the factor yet. Completing the factor gives the actor a session as that user, and access to any single sign-on application behind the account.
Workarounds
None. We recommend not relying on the email authenticator for multi-factor authentication until upgrading.
For more information
If you have any questions or comments about this advisory:
- Email us at [email protected]