CVE Database
/

CVE-2026-41577

Back to search

CVE-2026-41577

Published: Jun 2, 2026

Modified: Jun 3, 2026

PUBLISHED

Description

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored. This allows replay of expired assertions and acceptance of assertions intended for other service providers. This issue has been patched in versions 2025.12.5 and 2026.2.3.

VendorProductVersions

goauthentik

authentik

affected
< 2025.12.5
affected
< 2026.2.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now