Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c3m2-jqmq-pvp3 | authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user |
Thu, 04 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:* |
Wed, 03 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goauthentik
Goauthentik authentik |
|
| Vendors & Products |
Goauthentik
Goauthentik authentik |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue has been patched in versions 2025.12.5, 2026.2.3, and 2026.5.1. | |
| Title | authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T14:08:11.139Z
Reserved: 2026-05-18T22:07:37.436Z
Link: CVE-2026-47201
Updated: 2026-06-03T13:58:11.896Z
Status : Analyzed
Published: 2026-06-02T21:16:27.940
Modified: 2026-06-04T20:14:17.090
Link: CVE-2026-47201
No data.
OpenCVE Enrichment
Updated: 2026-06-04T22:00:14Z
Github GHSA