Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2026-42849

CVE-2026-42849 is a critical cross-site scripting (XSS) vulnerability in Authentik's AutosubmitStage, allowing attackers to execute malicious scripts via browser compatibility features. It affects versions prior to 2025.12.5 and 2026.2.3, but has been fixed in those updates.

publishedJun 2, 2026
last modifiedJul 22, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
28th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 24, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users of goauthentik authentik before versions 2025.12.5 or 2026.2.3

02

Real-world impact

Attackers could steal session cookies or impersonate users if they trick victims into interacting with malicious content.

03

Why this severity

CVSS 9.3 (critical): High risk due to network accessibility, low attack complexity, and potential for high confidentiality breaches.

04

What to do about it

official fix available
recommended steps
  1. 011. Upgrade Authentik to version 2025.12.5 or later.
  2. 022. Alternatively, upgrade to version 2026.2.3 or later.
  3. 033. Verify the upgrade was applied successfully.

NVD description stating patches exist in versions 2025.12.5 and 2026.2.3

05

Timeline

  1. Jun 2, 2026 · Jun 2, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 22, 2026 · 13d ago
    Advisory updated
    The NVD record was last revised.
  3. Jul 25, 2026 · 11d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →