CVE-2025-29928
CVSS 3.1 Score 8 of 10 (high)
Details
Summary
CVE-2025-29928 is a vulnerability affecting the open-source identity provider, authentik. Before versions 2024.12.4 and 2025.2.3, authentik, which by default uses cache-based session storage, could have its sessions deleted via the Web Interface or API without revoking the affected session. As a result, unauthorized access could be gained. To mitigate this risk, users should upgrade to authentik 2025.2.3 or 2024.12.4 as soon as possible, and in the interim, switch to cache-based session storage. This will, however, delete all existing sessions, necessitating re-authentication from users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.