authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goauthentik
Goauthentik authentik |
|
| Vendors & Products |
Goauthentik
Goauthentik authentik |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1. | |
| Title | authentik: SourceStage bypass via empty POST | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T20:31:20.323Z
Reserved: 2026-05-30T02:43:33.106Z
Link: CVE-2026-49448
No data.
Status : Received
Published: 2026-06-02T21:16:28.490
Modified: 2026-06-02T21:16:28.490
Link: CVE-2026-49448
No data.
OpenCVE Enrichment
Updated: 2026-06-03T04:30:05Z