{"id":"BIT-authentik-2024-52287","summary":"authentik performs insufficient validation of OAuth scopes","details":"authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.","aliases":["CVE-2024-52287","GHSA-v6m7-8j37-8f4v"],"modified":"2026-09-10T16:01:09.504715642Z","published":"2026-04-16T23:36:20.916Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:go:*:*"]},"references":[{"type":"FIX","url":"https://github.com/goauthentik/authentik/commit/e9c29e1644e9199b4ba58d2b10eb8c322138eea2"},{"type":"ADVISORY","url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-v6m7-8j37-8f4v"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52287"}],"affected":[{"package":{"name":"authentik","ecosystem":"Bitnami","purl":"pkg:bitnami/authentik"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2024.8.5"},{"introduced":"2024.10.0"},{"fixed":"2024.10.3"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/authentik/BIT-authentik-2024-52287.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}