- Description
- authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- authentik
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-287
- Hype score
- Not currently trending
CVE-2026-49448 - Critical authentication bypass in Authentik. Sending an empty POST bypasses the Source stage. CVSS 9.8. Update to 2025.12.6, 2026.2.4, or 2026.5.1 immediately. #CVE #Authentik #infosec #CVEAlert GET ALL FOR FREE https://t.co/m1WvckYOmX
@HugoValters
7 Jun 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-49448 authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This is… https://t.co/CZpITQLOhR ----- Traducción: CVE-2026-49448 aut… https://t.co/utmtNg
@infoflowcloud
3 Jun 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2248E771-C089-49F8-B370-D3E089534A60",
"versionEndExcluding": "2025.12.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2723A03F-6FA5-40D6-9D67-320CBC6538C4",
"versionEndExcluding": "2026.2.4",
"versionStartIncluding": "2026.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D092DE78-A8F3-4569-80F8-0289DF27CB2D",
"versionEndExcluding": "2026.5.1",
"versionStartIncluding": "2026.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]