---
cve: "CVE-2026-94606"
severity: "HIGH"
cvss: 8.9
epss: ""
vendor: "goauthentik"
kev: false
exploited: false
published: "2026-09-24 17:17:17"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-28T03:57:56+02:00"
---

# CVE-2026-94606

> 8.9 HIGH · 🧪 PoC

## Beschreibung

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a target user's password can substitute an attacker-controlled address, receive the one-time code, and finish enrolling the factor as the target. The target must not have enrolled the email factor already. Successful enrollment gives the actor a session as the target and access to single sign-on applications behind the account. Other authenticator types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- 0936c5b0ce31dc98f5f9eb4b06730a13f6da0333 (Commit)
- 71d3c21110023b914232d75b6c9089f472e2f73c (Commit)

## Referenzen

- <https://github.com/goauthentik/authentik/security/advisories/GHSA-qgqp-xh8r-v73r>
- <https://github.com/goauthentik/authentik/pull/25958>
- <https://github.com/goauthentik/authentik/pull/25963>
- <https://github.com/goauthentik/authentik/pull/25968>
- <https://github.com/goauthentik/authentik/pull/25973>
- <https://github.com/goauthentik/authentik/commit/01d4349f2aaa9beda532f92e2a251a17fefee9b3>
- <https://github.com/goauthentik/authentik/commit/1fcf9868133e5d05e266edbc1f6f3ee972baa3f9>
- <https://github.com/goauthentik/authentik/commit/c10ae83ebf8c61de2f1922edf1fab504d9f3b06f>
- <https://github.com/goauthentik/authentik/commit/ec41732339726fba477182c0906a8d930b145beb>
- <https://docs.goauthentik.io/releases/2026.2#fixed-in-202627>
- <https://docs.goauthentik.io/releases/2026.5#fixed-in-202657>
- <https://docs.goauthentik.io/releases/2026.8#fixed-in-202682>
- <https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7>
- <https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7>
- <https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-94606) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
