CVE-2023-46249: authentik potential installation takeover when default admin user is deleted
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint to create the default admin user, which can also optionally set the default admin users' password from an environment variable. When the user is deleted, the initial-setup flow used to configure authentik after the first installation becomes available again. authentik 2023.8.4 and 2023.10.2 fix this issue. As a workaround, ensure the default admin user (Username akadmin) exists and has a password set. It is recommended to use a very strong password for this user, and store it in a secure location like a password manager. It is also possible to deactivate the user to prevent any logins as akadmin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-46249?
CVE-2023-46249 is a vulnerability in authentik, an open-source Identity Provider, where an attacker can set the password of the default admin user without any authentication if the default admin user has been deleted.
What is the severity of CVE-2023-46249?
The severity of CVE-2023-46249 is critical, with a CVSS score of 9.7.
Which versions of authentik are affected by CVE-2023-46249?
Versions up to and including 2023.8.4 and versions between 2023.10.0 and 2023.10.2 of authentik are affected by CVE-2023-46249.
How can I fix CVE-2023-46249?
To fix CVE-2023-46249, it is recommended to update authentik to versions 2023.8.5 or higher for versions up to 2023.8.4, and versions between 2023.10.3 and 2023.10.5 for versions between 2023.10.0 and 2023.10.2.
Where can I find more information about CVE-2023-46249?
You can find more information about CVE-2023-46249 on the GitHub security advisory page: https://github.com/goauthentik/authentik/security/advisories/GHSA-rjvp-29xq-f62w