Tag
An improper access control vulnerability (CVE-2026-94609) in authentik allows users with delegated group management permissions to elevate their privileges to full administrator by adding themselves to superuser-flagged groups.