Home

Description

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the authentik server container through the test endpoint, which is intended to preview how a property mapping/policy works. authentik 2025.8.6, 2025.10.4, and 2025.12.4 fix this issue.

PUBLISHED Reserved 2026-01-30 | Published 2026-02-12 | Updated 2026-02-17 | Assigner GitHub_M




CRITICAL: 9.1CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-94: Improper Control of Generation of Code ('Code Injection')

Product status

>= 2021.3.1, < 2025.8.6
affected

>= 2025.10.0-rc1, < 2025.10.4
affected

>= 2025.10.0-rc1, < 2025.12.4
affected

References

github.com/...hentik/security/advisories/GHSA-qvxx-mfm6-626f

github.com/...ommit/c691afaef164cf73c10a26a944ef2f11dbb1ac80

github.com/...entik/authentik/releases/tag/version/2025.10.4

github.com/...entik/authentik/releases/tag/version/2025.12.4

github.com/...hentik/authentik/releases/tag/version/2025.8.6

cve.org (CVE-2026-25227)

nvd.nist.gov (CVE-2026-25227)

Download JSON