{"id":"BIT-authentik-2026-25227","summary":"authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint","details":"authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the authentik server container through the test endpoint, which is intended to preview how a property mapping/policy works. authentik 2025.8.6, 2025.10.4, and 2025.12.4 fix this issue.","aliases":["CVE-2026-25227","GHSA-qvxx-mfm6-626f"],"modified":"2026-09-10T16:01:10.670089222Z","published":"2026-04-16T23:36:32.477Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*"]},"references":[{"type":"FIX","url":"https://github.com/goauthentik/authentik/commit/c691afaef164cf73c10a26a944ef2f11dbb1ac80"},{"type":"ARTICLE","url":"https://github.com/goauthentik/authentik/releases/tag/version%2F2025.10.4"},{"type":"ARTICLE","url":"https://github.com/goauthentik/authentik/releases/tag/version%2F2025.12.4"},{"type":"ARTICLE","url":"https://github.com/goauthentik/authentik/releases/tag/version%2F2025.8.6"},{"type":"ADVISORY","url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-qvxx-mfm6-626f"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25227"}],"affected":[{"package":{"name":"authentik","ecosystem":"Bitnami","purl":"pkg:bitnami/authentik"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2021.3.1"},{"fixed":"2025.8.6"},{"introduced":"2025.10.0"},{"fixed":"2025.12.4"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/authentik/BIT-authentik-2026-25227.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}