Skip to main content

GHSA-qgqp-xh8r-v73r

Reported by @CallumBasham, @MattWidz

MFA bypass via recipient override in the email authenticator​

Summary​

An actor who knows a user's password could have the one-time code for the email based multi-factor authenticator delivered to an address they control, and then finish signing in as that user.

Patches​

authentik 2026.2.7, 2026.5.7 and 2026.8.2 fix this issue.

Impact​

Only deployments that enroll the email authenticator during an authentication or enrollment flow are affected. Other authenticator types are not affected.

During setup of the authenticator, the address that received the code was taken from the setup request instead of the address the flow had already established.

The target must not have enrolled the factor yet. Completing the factor gives the actor a session as that user, and access to any single sign-on application behind the account.

Workarounds​

None. We recommend not relying on the email authenticator for multi-factor authentication until upgrading.

For more information​

If you have any questions or comments about this advisory: