CVE-2026-47201 - authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
CVE ID :CVE-2026-47201 Published : June 2, 2026, 9:16 p.m. | 1 hour, 57 minutes ago Description :authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating...