Critical· 9.8official fix available
CVE-2026-49448
CVE-2026-49448 is a critical vulnerability in authentik (an open-source identity provider) where an attacker can bypass the Source stage by sending an empty POST request. This flaw affects versions prior to 2025.12.6, 2026.2.4, and 2026.5.1, allowing potential unauthorized access. A fix is available in the patched versions.
publishedJun 2, 2026
last modifiedJul 22, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
33th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 24, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Users of goauthentik authentik before versions 2025.12.6, 2026.2.4, or 2026.5.1
02
Real-world impact
Attackers could exploit this to bypass authentication mechanisms, potentially gaining unauthorized access to systems.
03
Why this severity
CVSS 9.8 (critical) due to high confidence, impact, and ease of exploitation via a simple empty POST.
04
What to do about it
official fix available
recommended steps
- 01Upgrade authentik to version 2025.12.6 or later.
- 02Alternatively, upgrade to version 2026.2.4 or 2026.5.1 if earlier versions are unavailable.
- 03Ensure the service restarts after applying the update to activate the fix.
NVD-referenced vendor advisory
05
Timeline
- Jun 2, 2026 · Jun 2, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07
References & advisories
- github.com/goauthentik/authentik/secur…exploitvendor advisory
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →