CVE-2026-49443: Goauthentik Authentik
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.
Affected products
- Goauthentik Authentik: before 2025.12.6 (fixed in 2025.12.6); from 2026.2.0, before 2026.2.4 (fixed in 2026.2.4); from 2026.5.0, before 2026.5.1 (fixed in 2026.5.1)
Published 2026-06-02. Last modified 2026-07-22.