What is CVE-2026-61574?
CVE-2026-61574 is a vulnerability in the open-source Authentik identity provider where the Remote Access Control endpoint list exposes all configured endpoints and their connection settings to any authenticated user, regardless of their access rights. This can lead to unauthorized information disclosure, and systems below versions 2026.2.6 and 2026.5.5 should be updated immediately.
Azərbaycanca: CVE-2026-61574 zəifliyi açıq mənbəli Authentik identiklik təminatçısındadır. Remote Access Control endpoint siyahısı istənilən autentifikasiya olunmuş istifadəçiyə bütün konfiqurasiya edilmiş endpointləri, o cümlədən həssas əlaqə parametrlərini təqdim edir. Bu, icazəsiz məlumat ifşasına səbəb ola bilər, ona görə də 2026.2.6 və 2026.5.5 versiyalarından aşağı sistemlər dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What information does CVE-2026-61574 expose in Authentik?
This vulnerability exposes the entire list of configured Remote Access Control endpoints and their sensitive connection settings to any authenticated user.
Which Authentik versions fix the CVE-2026-61574 vulnerability?
Systems running versions below 2026.2.6 and 2026.5.5 should be immediately updated to those versions or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.