CVE-2024-52287: Goauthentik Authentik
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.
Affected products
- Goauthentik Authentik: before 2024.8.5 (fixed in 2024.8.5); from 2024.10.0, before 2024.10.3 (fixed in 2024.10.3)
Published 2024-11-21. Last modified 2026-06-17.