Privilege Escalation in authentik via Groups API
An improper access control vulnerability (CVE-2026-94609) in authentik allows users with delegated group management permissions to elevate their privileges to full administrator by adding themselves to superuser-flagged groups.
CVE search metadata
CVE search record: CVE-2026-94609. Severity: high. CVSS: 8.8. KEV: no. Product: authentik (<= 2026.2.6), authentik (<= 2026.5.6), authentik (<= 2026.8.1). Brief: Privilege Escalation in authentik via Groups API. Brief link: https://feed.craftedsignal.io/briefs/2026-09-authentik-priv-esc/
CVE search record: CVE-2026-40172. Severity: high. CVSS: 8.1. EPSS: 0.53%. KEV: no. Product: authentik (<= 2026.2.6), authentik (<= 2026.5.6), authentik (<= 2026.8.1). Brief: Privilege Escalation in authentik via Groups API. Brief link: https://feed.craftedsignal.io/briefs/2026-09-authentik-priv-esc/
authentik is affected by a high-severity privilege escalation vulnerability (CVE-2026-94609) due to improper access control in the Groups API. The vulnerability exists within the GroupSerializer.validate_users() method, which fails to verify if the requesting user possesses the necessary authentik_core.enable_group_superuser permission when modifying the membership of a group flagged with is_superuser=True.
By design, authentik uses two distinct permissions: authentik_core.add_user_to_group for standard team roster management and authentik_core.enable_group_superuser for assigning superuser status. Because the validation logic only checks for the presence of the routine management permission, an attacker holding a delegated "helpdesk" or "user manager" role can inject themselves or other users into existing superuser groups. This effectively bypasses the intended RBAC controls, leading to full instance compromise. This flaw is a symmetric counterpart to a previously fixed vulnerability (CVE-2026-40172). Affected versions include releases within the 2026.2, 2026.5, and 2026.8 branches.
Attack Chain
- Attacker obtains a low-privileged API token or session belonging to an account with
authentik_core.add_user_to_grouppermissions. - Attacker interacts with the
/api/v3/core/groups/endpoint to list available groups within the authentik instance. - Attacker identifies a target group that has the
is_superuser=Trueattribute. - Attacker performs a
PATCHrequest to/api/v3/core/groups/{group_uuid}/containing the target group UUID. - The
GroupSerializer.validate_users()method processes the request, verifying only the routineadd_user_to_grouppermission. - The system authorizes the injection of the attacker-controlled user ID into the superuser group's membership list.
- The target user is instantly granted full administrative superuser privileges within the authentik environment.
- Attacker leverages full administrative access to manage SSO configurations, user accounts, and secret storage.
Impact
Successful exploitation allows a low-privileged user to gain full administrative control over the authentik instance. This facilitates unauthorized access to every tenant, interception of SSO authentication flows for downstream applications, modification of user accounts, and exfiltration or destruction of sensitive secrets and certificates managed by the instance.
Recommendation
Prioritize the immediate patching of all authentik instances to the fixed versions (2026.2.7, 2026.5.7, or 2026.8.2). If immediate patching is not possible, organizations must strictly audit and restrict the authentik_core.add_user_to_group permission, ensuring it is revoked from all non-administrative roles. Detection teams should monitor for unauthorized PATCH requests targeting group membership, particularly where the initiator lacks administrative status.
Immediate actions
Upgrade authentik to 2026.2.7, 2026.5.7, or 2026.8.2
Mitigations
Revoke authentik_core.add_user_to_group from non-administrative roles
CVE-2026-94609
Detection coverage 1
Detect Unauthorized PATCH Requests to authentik Groups API
highDetects potential CVE-2026-94609 exploitation attempts by monitoring PATCH requests to the groups API where the target action involves user modification.
Detection queries are available on the platform. Get full rules →