What is CVE-2026-55106?
CVE-2026-55106 was identified in 'authentik', an open-source identity provider. The diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter, allowing any party with API reach, including unauthenticated clients, to invoke it. Affected systems should prioritize updating to versions 2026.2.6 or 2026.5.5 to mitigate this unauthorized access risk.
Azərbaycanca: CVE-2026-55106 'authentik' açıq mənbəli identikasiya təminatçısında aşkarlanıb. LDAP Source API üzərindəki diaqnostik əməliyyat, oxuma icazəsi filtrini tətbiq etmir, bu da API-yə çıxışı olan hər hansı bir tərəfin (o cümlədən autentifikasiya olunmamış müştərilərin) bu funksiyanı çağırmasına imkan verir. Təsirə məruz qalan sistemlərdə təhlükəsizlik tədbiri olaraq 2026.2.6 və ya 2026.5.5 versiyalarına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which functionality in 'authentik' is affected by the CVE-2026-55106 vulnerability?
The diagnostic action on the LDAP Source API is affected. It does not enforce the object-level read-authorization filter, allowing any party with API reach, including unauthenticated clients, to invoke it.
Which versions are recommended to update to in order to mitigate CVE-2026-55106?
To mitigate the unauthorized access risk posed by this vulnerability, updating to versions 2026.2.6 or 2026.5.5 is recommended for affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.