Jens Langhammer
25 exploits
Active since Jul 2023
authentik <2023.4.3-2023.5.5 - SSRF
CVSS 8.3
authentik < 2023.8.5 - Improper Authentication via Missing PKCE Code Verifier Validation
CVSS 7.5
authentik <2023.8.4-2023.10.2 - Privilege Escalation
CVSS 9.6
authentik < 2023.8.5 - Improper Authentication via Missing PKCE Code Verifier Validation
CVSS 7.5
authentik < 2024.4.4, >=2024.6.0-rc1 < 2024.6.4 - Improper Authorization via API Endpoints
CVSS 7.5
authentik <2024.8.3-2024.6.5 - Auth Bypass
CVSS 9.0
authentik <2024.8.3-2024.6.5 - Info Disclosure
CVSS 6.5
authentik < 2025.4.3 - Improper Authentication via RAC Token Reuse
CVSS 9.6
authentik <2025.4.4, 2025.6.0-rc1-2025.6.3 - Info Disclosure
CVSS 7.4
authentik < 2025.4.3 - Improper Authentication via RAC Token Reuse
CVSS 9.6
authentik <2025.4.4, 2025.6.0-rc1-2025.6.3 - Info Disclosure
CVSS 7.4
authentik <2023.4.3-2023.5.5 - SSRF
CVSS 8.3
authentik <2023.5.6 and 2023.6.0-2023.6.2 - Username Enumeration via Recovery Flow
CVSS 5.3
authentik <2023.8.4-2023.10.2 - Privilege Escalation
CVSS 9.6
authentik < 2023.8.5 - Improper Authentication via Missing PKCE Code Verifier Validation
CVSS 7.5
authentik <2023.8.7 and 2023.10.0-2023.10.7 - PKCE Downgrade Authentication Bypass via Code Challenge Removal
CVSS 6.5
authentik < 2024.4.4, >=2024.6.0-rc1 < 2024.6.4 - Improper Authorization via API Endpoints
CVSS 7.5
authentik <2024.8.3-2024.6.5 - Auth Bypass
CVSS 9.0
authentik <2024.8.3-2024.6.5 - Info Disclosure
CVSS 6.5
authentik <2024.8.5,2024.10.3 - Info Disclosure
CVSS 7.2
authentik OAuth2 Redirect URI - Regex Validation Bypass
CVSS 9.8
authentik < 2024.8.5 - Observable Timing Discrepancy in Metrics Endpoint
CVSS 5.6
authentik <2024.12.4, <2025.2.3 - Info Disclosure
CVSS 8.0
authentik < 2025.4.3 - Improper Authentication via RAC Token Reuse
CVSS 9.6
authentik <2025.4.4, 2025.6.0-rc1-2025.6.3 - Info Disclosure
CVSS 7.4