SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-61574

HIGH · CVSS 8.8 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Remote Access Control endpoint in authentik versions prior to 2026.2.6 and 2026.5.5 is vulnerable, allowing any authenticated user to access a complete list of configured endpoints, including sensitive connection settings and stored credentials. This flaw can lead to unauthorized access to managed RDP, SSH, and VNC targets, potentially compromising systems beyond the user's intended permissions. Organizations utilizing authentik as their identity provider, particularly those with enterprise Remote Access Control, should prioritize upgrading to the patched versions to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61574
Severity
HIGH
CVSS
8.8
EPSS
0.36%

Original NVD Description

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The endpoint listing does not apply the access controls governing the endpoints, and the connection flow does not confirm that an endpoint belongs to the Remote Access Control application through which it was launched. Any authenticated user can therefore read every endpoint together with its host and stored credentials and can open a connection to an endpoint belonging to another application. This exposes stored credentials for managed RDP, SSH, and VNC targets and grants interactive access to systems the user was never authorized to reach. Deployments that do not use the enterprise Remote Access Control provider are not affected. This issue is fixed in versions 2026.2.6 and 2026.5.5.