CVE-2026-41569

MEDIUM CVSS 4.0: 6.9 EPSS 0.32%
Updated Jul 22, 2026
Goauthentik
Parameter Value
CVSS 6.9 (MEDIUM)
Affected Versions before 2026.2.3
Fixed In 2026.2.3
Type CWE-601 (Open Redirect)
Vendor Goauthentik
Public PoC No

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link can supply a wreply value on a different origin that passes the check (e.g. https://portal.example.com.evil.tld/), causing the victim's browser to POST the signed WS-Federation login response to attacker-controlled infrastructure.

This issue has been patched in version 2026.2.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Goauthentik Authentik
cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*
— 2026.2.3