What is CVE-2026-54730?
CVE-2026-54730 is a vulnerability in Authentik, an open-source identity provider. The issue allows the Google Chrome device-trust stages to advance the flow without confirming the out-of-band device attestation actually ran, affecting enterprise deployments prior to versions 2026.2.6 and 2026.5.5. Updating to the patched versions is strongly recommended.
Azərbaycanca: CVE-2026-54730, Authentik şəxsiyyət təminatçısında aşkar edilmiş zəiflikdir. Zəiflik, Google Chrome cihaz etibar mərhələlərində cihaz attestasiyasının həqiqətən icra edilib-edilmədiyini yoxlamadan axını irəlilətməklə bağlıdır. Bu, 2026.2.6 və 2026.5.5 versiyalarından əvvəlki enterpraiz tətbiqetmələrə təsir edir; müvafiq versiyalara yeniləmə tövsiyə olunur.
Related CVEs
link basis: shared vendor: Google
FAQ2
Which functionality in Authentik is affected by CVE-2026-54730?
The vulnerability affects the Google Chrome device-trust stages in Authentik, allowing the flow to advance without confirming that the out-of-band device attestation actually ran.
Which versions of Authentik are considered affected by CVE-2026-54730?
Enterprise deployments prior to versions 2026.2.6 and 2026.5.5 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.