Impact
A vulnerability in the SCIM group ingest functionality of Authentik Security allows an attacker who holds a source‑scoped provisioning token to gain full superuser rights. By creating a SCIM group whose name exactly matches an existing administrator group, the attacker can overwrite the group’s membership, causing the system to grant superuser privileges to the provisioning token and effectively lock out legitimate administrators. This flaw is a classic example of authentication‑related privilege escalation with CWE‑269 weaknesses.
Affected Systems
The issue affects Authentik Security authentik versions up to and including 2026.5.6. No specific patch version is listed, but the vulnerability exists in any installation that has not yet been updated beyond this release.
Risk and Exploitability
Based on the description, it is inferred that the attack vector would be the publicly exposed SCIM API endpoint, allowing an attacker to send a crafted SCIM group to the system. The CVSS score of 8.8 indicates a high‑severity vulnerability, and while the EPSS score is not available, the fact that the flaw requires only a valid source‑scoped SCIM token makes it relatively easy for an attacker with that token to exploit. The vulnerability is not currently listed by CISA in its KEV catalog. Exploitation would likely occur over the network when the API is exposed to attackers, and the impact is full administrative takeover of the Authentik deployment.
OpenCVE Enrichment