authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or /source/saml/*, causing the requests assigned to that worker to fail. Worker process termination and automatic restart do not destroy database-backed sessions, but continued malicious messages can cause a sustained share of legitimate traffic to fail. Other protocol implementations are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
CVE-2026-94613
This high-severity CVE scores 7.5 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit-prediction score not yet available (the EPSS model rescores nightly; freshly-published CVEs typically appear within 48 hours). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.5
- EG Score
- 7.5(low)
- EG Risk
- 38(Track)EG Risk 38/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity75% × 45%Exploitation0% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- Not listed
Published
September 24, 2026
Last Modified
September 24, 2026
Advisory Details (10)
Auto-updated Sep 24, 2026commit a029f5372295 (goauthentik/authentik)
Fix landed in goauthentik/authentik commit a029f5372295 — awaiting tagged release
https://github.com/goauthentik/authentik/commit/a029f5372295bfeb1e334855f78601681cdc9a2dcommit 732adad26bb9 (goauthentik/authentik)
Fix landed in goauthentik/authentik commit 732adad26bb9 — awaiting tagged release
https://github.com/goauthentik/authentik/commit/732adad26bb97361b6bf25ef138df5c16471ba1fcommit 4cf2f803b1c2 (goauthentik/authentik)
Fix landed in goauthentik/authentik commit 4cf2f803b1c2 — awaiting tagged release
https://github.com/goauthentik/authentik/commit/4cf2f803b1c2ef38c224eead375fd057a10ee8accommit 03d19d63b8d8 (goauthentik/authentik)
Fix landed in goauthentik/authentik commit 03d19d63b8d8 — awaiting tagged release
https://github.com/goauthentik/authentik/commit/03d19d63b8d8dd7bc3de7cf6e57c6df341a9fc86security: automated internal backport of patch 2190-libxml2-doctype.sec.patch to authentik-main
Fix merged in goauthentik/authentik PR #25974 on 2026-09-09 — awaiting tagged release
https://github.com/goauthentik/authentik/pull/25974security: automated internal backport of patch 2190-libxml2-doctype.sec.patch to authentik-2026.8
Fix merged in goauthentik/authentik PR #25969 on 2026-09-09 — awaiting tagged release
https://github.com/goauthentik/authentik/pull/25969security: automated internal backport of patch 2190-libxml2-doctype.sec.patch to authentik-2026.5
Fix merged in goauthentik/authentik PR #25964 on 2026-09-09 — awaiting tagged release
https://github.com/goauthentik/authentik/pull/25964security: automated internal backport of patch 2190-libxml2-doctype.sec.patch to authentik-2026.2
Fix merged in goauthentik/authentik PR #25959 on 2026-09-09 — awaiting tagged release
https://github.com/goauthentik/authentik/pull/25959Denial of Service via Malformed SAML Messages · Advisory · goauthentik/authentik · GitHub
https://github.com/goauthentik/authentik/security/advisories/GHSA-cxwx-9x59-28qmWeakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 3× in last 7d / 3× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-24 17:33 UTCEG score recompute
- 2026-09-24 16:27 UTCEG score recompute
- 2026-09-24 16:26 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(4)
What is CVE-2026-94613?
When was CVE-2026-94613 disclosed?
What is the CVSS score of CVE-2026-94613?
How do I remediate CVE-2026-94613?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-94613
Is Your Infrastructure Affected by CVE-2026-94613?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.