CVE-2026-42849 Details
Description
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.
A reflected cross-site scripting vulnerability has been identified in authentik, an open-source identity provider, in versions prior to 2025.12.5 and 2026.2.3. The issue arises from the AutosubmitStage in the Simple Flow Executor (SFE), which was made more compatible with legacy browsers. This vulnerability allows an attacker to exploit the SFE by redirecting web requests containing tokens, hijacking sessions, or performing other malicious actions. The flaw is particularly concerning when an OAuth2 provider is configured with a broad regex in the redirect_uri or through the state value. The SFE's previous use of jQuery without proper input sanitization left it vulnerable to such exploits.
Users can upgrade to authentik versions 2025.12.5 or 2026.2.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/goauthentik/authentik/security/advisories/GHSA-pgff-5mx8-fqj3 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| goauthentik authentik | < 2025.12.5 >= 2026.2.0, < 2026.2.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | New CVE Received | [email protected] |