CVE-2026-72537: high vulnerability (CVSS 8.8)
CVE-2026-72537 in Authentik Security allows privilege escalation via SCIM provisioning tokens. Attackers can take over or delete any account, including superusers, by exploiting username matching vulnerabilities without scope validation.
Prioritize patching Authentik to the latest version and audit SCIM provisioning token usage. Restrict token issuance and implement strong monitoring for anomalous account changes.
Authentik Security versions through 2026.5.6 are affected by CVE-2026-72537, a critical privilege escalation flaw. Attackers can use a SCIM provisioning token to create or overwrite accounts, including superuser accounts, by matching usernames with local accounts.
The vulnerability stems from inadequate scope validation in the SCIM user ingest function. This allows malicious actors to bypass account boundaries and rewrite or delete user accounts with limited credentials.
Organizations using Authentik should immediately update to a patched version and restrict SCIM provisioning token access. Monitoring for unusual account modifications is critical to mitigating potential exploitation.