Impact
This vulnerability allows a user who can modify source connections via the API to log into any account in another configured source, effectively bypassing authentication and enabling full impersonation of any user. It is a privilege‑escalation flaw (CWE‑287) that can grant an attacker complete access to the system without legitimate credentials. The likely attack vector is a privileged API user or a compromised account with permissions to change source connections, after which the attacker can alter the user or group association in a source and authenticate as any target user.
Affected Systems
The affected product is goauthentik's authentik identity provider. Versions before 2025.12.6, before 2026.2.4, and before 2026.5.1 are vulnerable. Any instance running these releases with exposed API endpoints is at risk.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Once an attacker has the ability to change a source connection—through legitimate privileges or credential compromise—this flaw enables them to impersonate any user, providing full system access. The attack is carried out remotely via authenticated API calls to the vulnerable endpoints, and requires initial privileged access but yields complete account takeover.
OpenCVE Enrichment