OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-94611

HIGH · CVSS 8.1 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The authentik identity provider in Kubernetes is vulnerable due to API serializers exposing stored credentials to accounts with view permissions, even if those accounts lack authorization to access sensitive configurations. This flaw can lead to unauthorized access to critical credentials, impacting the security of deployments that inadvertently grant view permissions to untrusted users. Organizations using authentik should prioritize upgrading to versions 2026.2.7, 2026.5.7, or 2026.8.2 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94611
Severity
HIGH
CVSS
8.1
EPSS
0.33%
Kubernetes

Original NVD Description

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications using a client or shared secret, and applications using a proxy provider. Deployments are affected when view permission is granted to accounts that are not intended to read these credentials; deployments where every viewer is permitted to read them are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.