CRITICAL🇵🇱 Wersja polska

CVE-2026-42849

CVSS 9.3v3.1pub. 2026-06-02upd. 2026-07-22

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.

🤖 AI Analysis
How it works

The vulnerability stems from the way stages are implemented in the SFE mechanism, which was designed to ensure compatibility with legacy browsers. Insufficient data sanitization in the AutosubmitStage component allows injection and execution of malicious JavaScript code in the context of the application. The attack requires user interaction (UI:R), but does not require any authentication or special privileges on the attacker's side, and its effects may extend beyond the source domain (S:C — scope change).

Impact

An attacker can gain access to sensitive user data (e.g., sessions, tokens) and perform unauthorized modifications in the context of a logged-in user, which in the case of an identity management system can lead to account takeover or unauthorized access to protected resources.

Mitigation & patch

Goauthentik Authentik should be updated to version 2025.12.5 or 2026.2.3 (or newer), in which the vulnerability has been fixed. Details are available in the vendor's references: https://github.com/goauthentik/authentik/security/advisories/GHSA-pgff-5mx8-fqj3

Who is affected

Goauthentik Authentik in versions prior to 2025.12.5 and prior to 2026.2.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Goauthentik Authentik

    APP
    Goauthentik
    < 2025.12.52026.2.0 – 2026.2.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-49448CRITICAL9.8PL ✓same product

Pominięcie etapu uwierzytelniania (Source Stage) w Goauthentik Authentik

CVE-2026-25227CRITICAL9.1PL ✓same product

RCE w authentik przez endpoint testowy mapowania właściwości

CVE-2024-47070CRITICAL9.0PL ✓same product

Pominięcie uwierzytelnienia przez nagłówek X-Forwarded-For w authentik

CVE-2023-46249CRITICAL9.6PL ✓same product

authentik — pominięcie uwierzytelnienia przy resetowaniu hasła admina

CVE-2023-26481CRITICAL9.1PL ✓same product

Authentik: przejęcie konta przez nieprawidłową walidację tokenu odzyskiwania