[Medium] CVE-2026-41577 – authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2...
Medium CVE-2026-41577 authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored....