OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-94613

HIGH · CVSS 7.5 EPSS 0.64% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Unauthenticated attackers can exploit a vulnerability in authentik's SAML implementation, leading to worker process termination and disruption of legitimate traffic. This can result in denial-of-service conditions for users relying on the identity provider. Organizations using authentik prior to versions 2026.2.7, 2026.5.7, and 2026.8.2 should prioritize updating to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94613
Severity
HIGH
CVSS
7.5
EPSS
0.64%

Original NVD Description

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or /source/saml/*, causing the requests assigned to that worker to fail. Worker process termination and automatic restart do not destroy database-backed sessions, but continued malicious messages can cause a sustained share of legitimate traffic to fail. Other protocol implementations are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.