
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25748 is a forward authentication bypass vulnerability in authentik, an open-source identity provider, caused by improper handling of malformed session cookies. When a crafted malformed cookie is submitted, the authentik Proxy Provider fails to set the X-Authentik-* headers, potentially granting unauthenticated access to protected applications. The vulnerability affects authentik versions up to and including 2025.10.3 and 2025.12.0–2025.12.3, and is only exploitable when the Proxy Provider is used with Traefik or Caddy as the reverse proxy. It was disclosed on February 12, 2026, with patches released the same day. The GitHub Security Advisory assigns a CVSS v3.1 score of 8.6 (High) with Scope: Changed, while NVD records a score of 7.5 (High) (GitHub Advisory, Red Hat CVE).
The root cause is classified as CWE-287 (Improper Authentication): when the authentik Proxy Provider receives a malformed session cookie, it fails to properly validate the session and does not populate the X-Authentik-* request headers that downstream applications rely on to enforce access control (GitHub Advisory). The attack vector is network-based, requires no privileges, no user interaction, and low attack complexity — an unauthenticated remote attacker simply sends an HTTP request with a crafted malformed cookie to an endpoint protected by forward authentication. The vulnerability is specific to deployments using Traefik or Caddy as the reverse proxy in conjunction with authentik's Proxy Provider forward authentication mode; other reverse proxies or authentication modes are not affected. The fix, committed in releases 2025.10.4 and 2025.12.4, includes a change to revalidate authentication when a session fails to load (outpost/proxyv2: revalidate auth if session fails to load) (GitHub Release 2025.10.4, GitHub Release 2025.12.4).
Successful exploitation allows an unauthenticated attacker to bypass authentication and gain unauthorized access to applications protected by the authentik Proxy Provider, with the severity of access depending on the downstream application's behavior — specifically, whether it grants access when X-Authentik-* headers are absent. The primary impact is high confidentiality exposure, as attackers may access sensitive data within protected applications without valid credentials. Integrity and availability are not directly impacted by this vulnerability itself, though unauthorized access could enable further malicious actions within the compromised application (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability has an EPSS score of approximately 0.026%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of required privileges make it straightforward to exploit in environments meeting the preconditions (Traefik or Caddy with authentik forward authentication). A Nuclei detection template pull request was submitted to the ProjectDiscovery repository, indicating community interest in automated detection (Nuclei Templates PR).
Cookie header.X-Authentik-* headers are not set. If the downstream application grants access when these headers are missing, the attacker gains unauthorized entry.X-Authentik-* headers forwarded.X-Authentik-Username / X-Authentik-* header values, particularly from IP addresses with no prior authenticated sessions.Upgrade authentik to version 2025.10.4 (for the 2025.10.x branch) or 2025.12.4 (for the 2025.12.x branch), both released on February 12, 2026 (GitHub Release 2025.10.4, GitHub Release 2025.12.4). There are no configuration-based workarounds available. If an immediate upgrade is not possible, the authentik project recommends disabling reverse proxy entries for any applications using forward authentication until the upgrade can be performed (GitHub Advisory). Organizations should also review access logs for any suspicious activity involving malformed cookies or unexpected authentication bypass incidents.
The vulnerability was reported by researcher imlonghao and disclosed via GitHub Security Advisory on February 12, 2026 (GitHub Advisory). The Hacker Wire covered the disclosure and shared it on Mastodon and Bluesky, generating community awareness. A Reddit thread in r/selfhosted noted the patch release and encouraged users to update, reflecting the active self-hosted community around authentik (Reddit). Community reaction was generally measured, with no reports of active exploitation amplifying concern.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."