CVE-2025-29928

CVSS 3.1 Score 8 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 384

Summary

CVE-2025-29928 is a vulnerability affecting the open-source identity provider, authentik. Before versions 2024.12.4 and 2025.2.3, authentik, which by default uses cache-based session storage, could have its sessions deleted via the Web Interface or API without revoking the affected session. As a result, unauthorized access could be gained. To mitigate this risk, users should upgrade to authentik 2025.2.3 or 2024.12.4 as soon as possible, and in the interim, switch to cache-based session storage. This will, however, delete all existing sessions, necessitating re-authentication from users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share