{"id":"CVE-2026-25748","summary":"authentik has a forward authentication bypass with broken cookie","details":"authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. When a malicious cookie was used, none of the authentik-specific X-Authentik-* headers were set which depending on application can grant access to an attacker. authentik 2025.10.4 and 2025.12.4 fix this issue.","aliases":["BIT-authentik-2026-25748","GHSA-fj56-5763-j8pp"],"modified":"2026-08-12T03:51:28.443811687Z","published":"2026-02-12T19:36:45.631Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25748.json"},"references":[{"type":"WEB","url":"https://github.com/goauthentik/authentik/releases/tag/version%2F2025.10.4"},{"type":"WEB","url":"https://github.com/goauthentik/authentik/releases/tag/version%2F2025.12.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25748.json"},{"type":"ADVISORY","url":"https://github.com/goauthentik/authentik/security/advisories/GHSA-fj56-5763-j8pp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25748"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/goauthentik/authentik","events":[{"introduced":"6d1c7f90e2da9c2c4bc27a6c8784c4130e6fe822"},{"fixed":"7b0f19465b64905b49357e10dc15abffec3737d0"},{"fixed":"19ad8d3ae3f266ec1096bc4461fdf6bcda1aa079"}],"database_specific":{"extracted_events":[{"introduced":"2025.10.0-rc1"},{"fixed":"2025.10.4"},{"fixed":"2025.12.4"}],"source":"AFFECTED_FIELD"}}],"versions":["version/2025.10.3","version/2025.10.2","version/2025.10.1","version/2025.10.0","version/2025.10.0-rc3","version/2025.10.0-rc2","version/2025.10.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25748.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}