{"api_version":"v1","generated_at":"2026-10-08T02:40:00+00:00","product":{"cve_count":45,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-goauthentik-authentik-ceb66f755381","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/authentik","name":"authentik","next_cursor":null,"observations":[{"affected":"authentik: < 2026.2.7, >= 2026.5.0, < 2026.5.7, >= 2026.8.0, < 2026.8.2","affected_versions_present":true,"cve_id":"CVE-2026-94606","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94606","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-05T15:33:40.648Z","patch_url":"","primary_source":"","published":"2026-09-24T16:23:30.925Z"},{"affected":"authentik: < 2026.2.7, >= 2026.5.0, < 2026.5.7, >= 2026.8.0, < 2026.8.2","affected_versions_present":true,"cve_id":"CVE-2026-94609","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94609","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-28T15:41:52.662Z","patch_url":"","primary_source":"","published":"2026-09-24T16:20:45.703Z"},{"affected":"authentik: < 2026.2.7, >= 2026.5.0, < 2026.5.7, >= 2026.8.0, < 2026.8.2","affected_versions_present":true,"cve_id":"CVE-2026-94611","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94611","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T17:08:17.710Z","patch_url":"","primary_source":"","published":"2026-09-24T16:18:46.592Z"},{"affected":"authentik: < 2026.2.7, >= 2026.5.0, < 2026.5.7, >= 2026.8.0, < 2026.8.2","affected_versions_present":true,"cve_id":"CVE-2026-94612","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94612","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T17:15:23.385Z","patch_url":"","primary_source":"","published":"2026-09-24T16:16:33.503Z"},{"affected":"authentik: < 2026.2.7, >= 2026.5.0, < 2026.5.7, >= 2026.8.0, < 2026.8.2","affected_versions_present":true,"cve_id":"CVE-2026-94613","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94613","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-29T02:53:23.285Z","patch_url":"","primary_source":"","published":"2026-09-24T16:13:17.785Z"},{"affected":"< 2026.2.6; >= 2026.5.0, < 2026.5.5","affected_versions_present":true,"cve_id":"CVE-2026-57580","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57580","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-18T17:45:24.521Z","patch_url":"","primary_source":"","published":"2026-08-18T17:00:19.209Z"},{"affected":"< 2026.2.6; >= 2026.5.0, < 2026.5.5","affected_versions_present":true,"cve_id":"CVE-2026-55106","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55106","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-18T19:07:09.460Z","patch_url":"","primary_source":"","published":"2026-08-18T16:59:12.476Z"},{"affected":"< 2026.2.6; >= 2026.5.0, < 2026.5.5","affected_versions_present":true,"cve_id":"CVE-2026-61574","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61574","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-19T15:04:08.783Z","patch_url":"","primary_source":"","published":"2026-08-18T16:57:47.043Z"},{"affected":"< 2026.2.6; >= 2026.5.0, < 2026.5.5","affected_versions_present":true,"cve_id":"CVE-2026-54730","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54730","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-18T17:21:10.123Z","patch_url":"","primary_source":"","published":"2026-08-18T16:55:29.771Z"},{"affected":"< 2025.12.6; < 2026.2.4; < 2026.5.1","affected_versions_present":true,"cve_id":"CVE-2026-49448","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49448","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T12:46:25.064Z","patch_url":"","primary_source":"","published":"2026-06-02T20:31:20.323Z"},{"affected":"< 2025.12.6; < 2026.2.4; < 2026.5.1","affected_versions_present":true,"cve_id":"CVE-2026-49443","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49443","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T13:59:41.215Z","patch_url":"","primary_source":"","published":"2026-06-02T20:31:09.108Z"},{"affected":"< 2025.12.5; < 2026.2.3; < 2026.5.1","affected_versions_present":true,"cve_id":"CVE-2026-47201","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47201","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T14:08:11.139Z","patch_url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-c3m2-jqmq-pvp3","primary_source":"","published":"2026-06-02T20:30:55.674Z"},{"affected":"< 2025.12.5; < 2026.2.3","affected_versions_present":true,"cve_id":"CVE-2026-42849","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42849","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T19:05:26.760Z","patch_url":"","primary_source":"","published":"2026-06-02T20:30:43.839Z"},{"affected":"< 2026.2.3","affected_versions_present":true,"cve_id":"CVE-2026-41569","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41569","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T14:29:52.842Z","patch_url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-995q-72cw-cfw3","primary_source":"","published":"2026-06-02T20:30:21.664Z"},{"affected":"< 2025.12.5; < 2026.2.3","affected_versions_present":true,"cve_id":"CVE-2026-41577","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41577","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T13:18:23.260Z","patch_url":"","primary_source":"","published":"2026-06-02T17:12:26.690Z"},{"affected":"< 2025.12.5; >= 2026.2.0-rc1, < 2026.2.3","affected_versions_present":true,"cve_id":"CVE-2026-40172","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40172","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-22T19:15:18.353Z","patch_url":"","primary_source":"","published":"2026-05-22T19:00:52.278Z"},{"affected":"< 2025.12.5; >= 2026.2.0-rc1, < 2026.2.3","affected_versions_present":true,"cve_id":"CVE-2026-40166","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40166","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T18:47:57.418Z","patch_url":"","primary_source":"","published":"2026-05-22T18:52:46.650Z"},{"affected":"< 2025.12.5; >= 2026.2.0-rc1, < 2026.2.3","affected_versions_present":true,"cve_id":"CVE-2026-40165","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40165","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-21T14:13:20.329Z","patch_url":"","primary_source":"","published":"2026-05-20T23:35:18.309Z"},{"affected":"< 2025.8.6; >= 2025.10.0-rc1, < 2025.10.4; >= 2025.10.0-rc1, < 2025.12.4","affected_versions_present":true,"cve_id":"CVE-2026-25922","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25922","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-17T16:19:14.739Z","patch_url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-jh35-c4cc-wjm4","primary_source":"","published":"2026-02-12T19:38:16.850Z"},{"affected":">= 2025.10.0-rc1, < 2025.10.4; >= 2025.10.0-rc1, < 2025.12.4","affected_versions_present":true,"cve_id":"CVE-2026-25748","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25748","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-17T15:53:01.301Z","patch_url":"","primary_source":"","published":"2026-02-12T19:36:45.631Z"},{"affected":">= 2021.3.1, < 2025.8.6; >= 2025.10.0-rc1, < 2025.10.4; >= 2025.10.0-rc1, < 2025.12.4","affected_versions_present":true,"cve_id":"CVE-2026-25227","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25227","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-17T15:43:53.801Z","patch_url":"https://github.com/goauthentik/authentik/commit/c691afaef164cf73c10a26a944ef2f11dbb1ac80","primary_source":"","published":"2026-02-12T19:25:26.932Z"},{"affected":"< 2025.10.2; < 2025.8.5","affected_versions_present":true,"cve_id":"CVE-2025-64708","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64708","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-20T15:48:29.627Z","patch_url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-ch7q-53v8-73pc","primary_source":"","published":"2025-11-19T17:03:22.858Z"},{"affected":"< 2025.10.2; < 2025.8.5","affected_versions_present":true,"cve_id":"CVE-2025-64521","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64521","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-19T21:09:40.560Z","patch_url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-xr73-jq5p-ch8r","primary_source":"","published":"2025-11-19T17:03:19.703Z"},{"affected":"<= 2025.4.3, < 2025.4.4; >= 2025.6.0-rc1, < 2025.6.4","affected_versions_present":true,"cve_id":"CVE-2025-53942","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-53942","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-07-23T20:49:29.415Z","patch_url":"https://github.com/goauthentik/authentik/commit/7a4c6b9b50f8b837133a7a1fd2cb9b7f18a145cd","primary_source":"","published":"2025-07-23T20:35:07.243Z"},{"affected":">= 2025.6.0-rc1, < 2025.6.3; < 2025.4.3","affected_versions_present":true,"cve_id":"CVE-2025-52553","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-52553","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-27T15:50:17.417Z","patch_url":"https://github.com/goauthentik/authentik/commit/0e07414e9739b318cff9401a413a5fe849545325","primary_source":"","published":"2025-06-27T15:03:13.015Z"},{"affected":"< 2024.12.4; < 2025.2.3","affected_versions_present":true,"cve_id":"CVE-2025-29928","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-29928","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-28T15:41:39.773Z","patch_url":"https://github.com/goauthentik/authentik/commit/71294b7deb6eb5726a782de83b957eaf25fc4cf6","primary_source":"","published":"2025-03-28T14:42:39.542Z"},{"affected":"< 2024.10.4","affected_versions_present":true,"cve_id":"CVE-2024-11623","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-11623","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-12T17:10:12.746Z","patch_url":"https://github.com/goauthentik/authentik/pull/12092","primary_source":"","published":"2025-02-04T13:34:11.029Z"},{"affected":"< 2024.8.5; >= 2024.10.0-rc1, < 2024.10.3","affected_versions_present":true,"cve_id":"CVE-2024-52287","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-52287","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-11-21T21:05:11.287Z","patch_url":"https://github.com/goauthentik/authentik/commit/e9c29e1644e9199b4ba58d2b10eb8c322138eea2","primary_source":"","published":"2024-11-21T17:23:40.640Z"},{"affected":"< 2024.8.5; >= 2024.10.0-rc1, < 2024.10.3","affected_versions_present":true,"cve_id":"CVE-2024-52289","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-52289","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-23T18:21:58.900Z","patch_url":"https://github.com/goauthentik/authentik/commit/85bb638243c8d7ea42ddd3b15b3f51a90d2b8c54","primary_source":"","published":"2024-11-21T17:18:41.161Z"},{"affected":"< 2024.8.5; >= 2024.10.0-rc1, < 2024.10.3","affected_versions_present":true,"cve_id":"CVE-2024-52307","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-52307","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-11-27T16:03:20.897Z","patch_url":"https://github.com/goauthentik/authentik/commit/5ea4580884f99369f0ccfe484c04cb03a66e65b8","primary_source":"","published":"2024-11-21T17:14:51.677Z"},{"affected":">= 2024.8.0-rc1, < 2024.8.3; < 2024.6.5","affected_versions_present":true,"cve_id":"CVE-2024-47077","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-47077","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-27T17:51:19.674Z","patch_url":"https://github.com/goauthentik/authentik/commit/22e586bd8cdc3d1db8a0f18314d76f82371129b2","primary_source":"","published":"2024-09-27T15:26:20.683Z"},{"affected":">= 2024.8.0-rc1, < 2024.8.3; < 2024.6.5","affected_versions_present":true,"cve_id":"CVE-2024-47070","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-47070","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-27T17:55:55.382Z","patch_url":"https://github.com/goauthentik/authentik/commit/78f7b04d5a62b2a9d4316282a713c2c7857dbe29","primary_source":"","published":"2024-09-27T15:18:03.999Z"},{"affected":"< 2024.4.4; >= 2024.6.0-rc1, < 2024.6.4","affected_versions_present":true,"cve_id":"CVE-2024-42490","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-42490","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-22T16:04:32.442Z","patch_url":"https://github.com/goauthentik/authentik/commit/19318d4c00bb02c4ec3c4f8f15ac2e1dbe8d846c","primary_source":"","published":"2024-08-22T15:34:45.815Z"},{"affected":"< 2024.6.0; < 2024.4.3; < 2024.2.4","affected_versions_present":true,"cve_id":"CVE-2024-38371","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-38371","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T04:04:25.257Z","patch_url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-jq3m-37m7-gp45","primary_source":"","published":"2024-06-28T17:58:48.169Z"},{"affected":"< 2024.6.0; < 2024.4.2; < 2024.2.4","affected_versions_present":true,"cve_id":"CVE-2024-37905","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-37905","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T04:04:23.359Z","patch_url":"","primary_source":"","published":"2024-06-28T17:09:24.090Z"},{"affected":"< 2023.8.7; >= 2023.10.0, < 2023.10.7","affected_versions_present":true,"cve_id":"CVE-2024-23647","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-23647","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-17T21:29:18.763Z","patch_url":"https://github.com/goauthentik/authentik/commit/38e04ae12720e5d81b4f7ac77997eb8d1275d31a","primary_source":"","published":"2024-01-30T16:10:55.999Z"},{"affected":"<= 2023.10.5; <= 2023.8.5","affected_versions_present":true,"cve_id":"CVE-2024-21637","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-21637","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-17T21:09:15.907Z","patch_url":"https://github.com/goauthentik/authentik/releases/tag/version%2F2023.10.6","primary_source":"","published":"2024-01-11T05:49:44.123Z"},{"affected":"< 2023.10.4; < 2023.8.5","affected_versions_present":true,"cve_id":"CVE-2023-48228","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-48228","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T21:23:39.088Z","patch_url":"https://github.com/goauthentik/authentik/pull/7666","primary_source":"","published":"2023-11-21T20:48:32.552Z"},{"affected":"< 2023.8.4; >= 2023.10.0, < 2023.10.2","affected_versions_present":true,"cve_id":"CVE-2023-46249","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-46249","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-05T15:55:53.846Z","patch_url":"https://github.com/goauthentik/authentik/commit/261879022d25016d58867cf1f24e90b81ad618d0","primary_source":"","published":"2023-10-31T15:20:35.166Z"},{"affected":">= 2023.6.0, < 2023.6.2; < 2023.5.6","affected_versions_present":true,"cve_id":"CVE-2023-39522","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-39522","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-01T20:19:58.448Z","patch_url":"https://github.com/goauthentik/authentik/commit/aa874dd92a770d5f8cd8f265b7cdd31cd73a4599","primary_source":"","published":"2023-08-29T17:23:37.092Z"},{"affected":"< 2023.4.3; >= 2023.5.0, < 2023.5.5","affected_versions_present":true,"cve_id":"CVE-2023-36456","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-36456","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-11-14T14:10:35.658Z","patch_url":"https://github.com/goauthentik/authentik/commit/15026748d19d490eb2baf9a9566ead4f805f7dff","primary_source":"","published":"2023-07-06T18:24:03.308Z"},{"affected":"< 2023.2.3; < 2023.1.3; < 2022.12.2","affected_versions_present":true,"cve_id":"CVE-2023-26481","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-26481","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-25T15:01:34.943Z","patch_url":"","primary_source":"","published":"2023-03-04T00:30:16.509Z"},{"affected":">= 2022.11.0, < 2022.11.4; >= 2022.10.0, < 2022.10.4","affected_versions_present":true,"cve_id":"CVE-2022-46172","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-46172","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-11T15:46:38.946Z","patch_url":"","primary_source":"","published":"2022-12-28T06:16:21.985Z"},{"affected":">= 2022.11.0, < 2022.11.4; < 2022.10.4","affected_versions_present":true,"cve_id":"CVE-2022-23555","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23555","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-11T15:48:20.256Z","patch_url":"","primary_source":"","published":"2022-12-28T00:12:35.912Z"},{"affected":"< 2022.10.2; >= 2022.11.0, < 2022.11.2","affected_versions_present":true,"cve_id":"CVE-2022-46145","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-46145","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T16:33:01.881Z","patch_url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-mjfw-54m5-fvjf","primary_source":"","published":"2022-12-02T17:12:42.046Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"goauthentik"}}
