CVE-2024-52287: Goauthentik Authentik

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.

Affected products

  • Goauthentik Authentik: before 2024.8.5 (fixed in 2024.8.5); from 2024.10.0, before 2024.10.3 (fixed in 2024.10.3)

Published 2024-11-21. Last modified 2026-06-17.