CVE-CVE-2026-94609
Severity
HIGH
CVSS Score
8.8
Description
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deploym...
PoCs for CVE-CVE-2026-94609
CVE-2026-94609
General
Python
0
anthonyk2923
2026-09-24