CVE-2026-72537
8.8Authentik Security · authentik
A privilege escalation vulnerability in Authentik Security authentik allows authenticated users to gain unauthorized elevated access.
Executive summary
A high-severity privilege escalation flaw in Authentik Security authentik allows authenticated attackers to compromise system integrity and confidentiality.
Vulnerability
This vulnerability is caused by improper privilege management, allowing an authenticated user with low privileges to escalate their access level. The attack vector is network-based and requires low privileges to initiate.
Business impact
Successful exploitation of this vulnerability allows an attacker to bypass intended access controls, potentially gaining administrative control over the authentication service. Given the CVSS score of 8.8, this poses a significant risk to the entire identity provider infrastructure, likely leading to total data compromise and unauthorized access to downstream integrated applications.
Remediation
Immediate Action: Upgrade to a version beyond 2026.5.6 as specified in the vendor security advisory to remediate the flaw.
Proactive Monitoring: Review audit logs for unusual user role changes or unauthorized administrative actions performed by low-privileged accounts.
Compensating Controls: Implement strict role-based access control (RBAC) policies and limit administrative access to the authentik dashboard to trusted internal networks.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
The vulnerability represents a critical risk to identity management services. Administrators must prioritize updating the authentik instance to a patched version immediately to prevent unauthorized privilege escalation and subsequent system-wide compromise.