CVE-2026-42849
CVE-2026-42849 is a critical cross-site scripting (XSS) vulnerability in Authentik's AutosubmitStage, allowing attackers to execute malicious scripts via browser compatibility features. It affects versions prior to 2025.12.5 and 2026.2.3, but has been fixed in those updates.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of goauthentik authentik before versions 2025.12.5 or 2026.2.3
Real-world impact
Attackers could steal session cookies or impersonate users if they trick victims into interacting with malicious content.
Why this severity
CVSS 9.3 (critical): High risk due to network accessibility, low attack complexity, and potential for high confidentiality breaches.
What to do about it
- 011. Upgrade Authentik to version 2025.12.5 or later.
- 022. Alternatively, upgrade to version 2026.2.3 or later.
- 033. Verify the upgrade was applied successfully.
NVD description stating patches exist in versions 2025.12.5 and 2026.2.3
Timeline
- Jun 2, 2026 · Jun 2, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/goauthentik/authentik/secur…vendor advisory