CVE-2023-46249: authentik potential installation takeover when default admin user is deleted

Published Oct 31, 2023
·
Updated

authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint to create the default admin user, which can also optionally set the default admin users' password from an environment variable. When the user is deleted, the initial-setup flow used to configure authentik after the first installation becomes available again. authentik 2023.8.4 and 2023.10.2 fix this issue. As a workaround, ensure the default admin user (Username akadmin) exists and has a password set. It is recommended to use a very strong password for this user, and store it in a secure location like a password manager. It is also possible to deactivate the user to prevent any logins as akadmin.

Affected Software

2 affected components
goauthentik Authentik<2023.8.4
goauthentik Authentik>=2023.10.0<2023.10.2

Event History

Oct 31, 2023
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2023-46249?

CVE-2023-46249 is a vulnerability in authentik, an open-source Identity Provider, where an attacker can set the password of the default admin user without any authentication if the default admin user has been deleted.

2

What is the severity of CVE-2023-46249?

The severity of CVE-2023-46249 is critical, with a CVSS score of 9.7.

3

Which versions of authentik are affected by CVE-2023-46249?

Versions up to and including 2023.8.4 and versions between 2023.10.0 and 2023.10.2 of authentik are affected by CVE-2023-46249.

4

How can I fix CVE-2023-46249?

To fix CVE-2023-46249, it is recommended to update authentik to versions 2023.8.5 or higher for versions up to 2023.8.4, and versions between 2023.10.3 and 2023.10.5 for versions between 2023.10.0 and 2023.10.2.

5

Where can I find more information about CVE-2023-46249?

You can find more information about CVE-2023-46249 on the GitHub security advisory page: https://github.com/goauthentik/authentik/security/advisories/GHSA-rjvp-29xq-f62w

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203