Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Goauthentik

First CVE: Dec 2, 2022Active for: 4 yearsTotal CVEs: 33
42.0
VTI Score
High

Goauthentik is a focused open-source identity and access management platform that consolidates authentication and authorization for downstream applications, placing it in a sensitive position within organizational infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster durably around authentication bypass, authorization failures, privilege escalation, and cross-site scripting in its single flagship product, Authentik—weakness classes that strike at the core trust mechanisms identity platforms must enforce. These recurrent flaws reflect the complex state management, token handling, and access-control logic inherent to identity brokers, and a compromise of such a platform can cascade to unauthorized access across all integrated applications. Defenders should treat Authentik updates as high-priority and maintain strict network segmentation around identity infrastructure; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
6.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Goauthentik over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 2022
3 years ago
Most Recent CVE
Jun 2, 2026
52 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-49448CRITICAL
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been p
Jun 2, 20269.841NONO
CVE-2026-42849CRITICAL
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the
Jun 2, 20269.338NONO
CVE-2026-49443HIGH
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in on
Jun 2, 20268.837NONO
CVE-2026-47201HIGH
authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping whe
Jun 2, 20268.535NONO
CVE-2022-46145CRITICAL
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the defau
Dec 2, 20229.831NONO
CVE-2023-48228CRITICAL
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authen
Nov 21, 20239.830NONO
CVE-2026-25922HIGH
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verificati
Feb 12, 20268.829NONO
CVE-2022-23555HIGH
authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reu
Dec 28, 20228.829NONO
CVE-2026-41577HIGH
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Condit
Jun 2, 20267.528NONO
CVE-2026-41569MEDIUM
authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check ra
Jun 2, 20266.127NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
30%
42%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (81.8%)
High6 (18.2%)
Unknown0 (0.0%)
User Interaction
None23 (69.7%)
Unknown0 (0.0%)
Required10 (30.3%)
Privileges Required
Low7 (21.2%)
High4 (12.1%)
None22 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Goauthentik.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Goauthentik — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Goauthentik's Products

View all 2 CNAs →

Top CWEs