Goauthentik is a focused open-source identity and access management platform that consolidates authentication and authorization for downstream applications, placing it in a sensitive position within organizational infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster durably around authentication bypass, authorization failures, privilege escalation, and cross-site scripting in its single flagship product, Authentik—weakness classes that strike at the core trust mechanisms identity platforms must enforce. These recurrent flaws reflect the complex state management, token handling, and access-control logic inherent to identity brokers, and a compromise of such a platform can cascade to unauthorized access across all integrated applications. Defenders should treat Authentik updates as high-priority and maintain strict network segmentation around identity infrastructure; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goauthentik over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49448CRITICAL authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been p | Jun 2, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-42849CRITICAL authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the | Jun 2, 2026 | 9.3 | 38 | NO | NO |
CVE-2026-49443HIGH authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in on | Jun 2, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-47201HIGH authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping whe | Jun 2, 2026 | 8.5 | 35 | NO | NO |
CVE-2022-46145CRITICAL authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the defau | Dec 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-48228CRITICAL authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authen | Nov 21, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-25922HIGH authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verificati | Feb 12, 2026 | 8.8 | 29 | NO | NO |
CVE-2022-23555HIGH authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reu | Dec 28, 2022 | 8.8 | 29 | NO | NO |
CVE-2026-41577HIGH authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Condit | Jun 2, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-41569MEDIUM authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check ra | Jun 2, 2026 | 6.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goauthentik.
Media articles that mention a CVE ID that affects a product developed by Goauthentik — matched by CVE ID, not by vendor name.