authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this account was possible even when the account was deactivated. Other permissions are correctly applied and federation with other providers still take assigned policies correctly into account. authentik versions 2025.8.5 and 2025.10.2 fix this issue. A workaround involves adding a policy to the application that explicitly checks if the service account is still valid, and deny access if not.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xr73-jq5p-ch8r authentik allows a deactivated Service account to authenticate to OAuth
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 20 Nov 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Goauthentik
Goauthentik authentik
CPEs cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*
Vendors & Products Goauthentik
Goauthentik authentik

Wed, 19 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Description authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this account was possible even when the account was deactivated. Other permissions are correctly applied and federation with other providers still take assigned policies correctly into account. authentik versions 2025.8.5 and 2025.10.2 fix this issue. A workaround involves adding a policy to the application that explicitly checks if the service account is still valid, and deny access if not.
Title authentik deactivated service accounts can authenticate to OAuth
Weaknesses CWE-289
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-19T21:09:40.560Z

Reserved: 2025-11-05T21:15:39.400Z

Link: CVE-2025-64521

cve-icon Vulnrichment

Updated: 2025-11-19T21:09:36.543Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-19T17:15:52.033

Modified: 2025-11-20T18:56:52.340

Link: CVE-2025-64521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.