CVE-2026-42849

CRITICAL CVSS 3.1: 9.3 EPSS 0.47%
Updated Jul 22, 2026
Goauthentik
Parameter Value
CVSS 9.3 (CRITICAL)
Affected Versions 2026.2.0 — 2026.2.3
Fixed In 2025.12.5
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Goauthentik
Public PoC No

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Goauthentik Authentik
cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*
— 2025.12.5
Goauthentik Authentik
cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*
2026.2.0 2026.2.3