What is CVE-2026-72537?
CVE-2026-72537 is a critical privilege escalation vulnerability in Authentik Security authentik through version 2026.5.6. An attacker with a source-scoped SCIM provisioning token can take over any user account, including superusers, by provisioning a SCIM user that matches an existing local username. Immediate software update to the latest patched version is strongly recommended.
Azərbaycanca: CVE-2026-72537 Authentik Security authentik 2026.5.6 və əvvəlki versiyalarda müəyyən edilmiş kritik imtiyaz yüksəltmə zəifliyidir. Mənbə məhdudiyyətli SCIM provisioning token-ə sahib hücumçu, mövcud istifadəçi adı ilə uyğunlaşan SCIM istifadəçisi təmin etməklə superuser daxil istənilən hesabı ələ keçirə bilər. Dərhal proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
What software is affected by CVE-2026-72537 and which versions are at risk?
This vulnerability affects Authentik Security authentik software. Specifically, version 2026.5.6 and all prior versions are susceptible to this critical privilege escalation issue.
How can an attacker take over a superuser account using CVE-2026-72537?
An attacker with a source-scoped SCIM provisioning token can take over any account, including superusers, by provisioning a SCIM user with a username that matches an existing local user on the system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.