Impact
A source‑scoped SCIM provisioning token can be used to provision SCIM users that match existing local accounts by username. The ingest function accepts such users without validating the token’s scope boundaries, allowing the attacker to create or modify any local account, including superusers. The flaw is an improper authorization weakness (CWE‑269) that enables attackers to undermine application security and take full control of the system.
Affected Systems
Authentik Security authentik versions up to and including 2026.5.6 are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector involves interacting with the SCIM provisioning API using a token that has been granted a limited, but improperly enforced, scope—an attacker can therefore submit a crafted SCIM request over an authenticated channel to manipulate any user account.
OpenCVE Enrichment