No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 03 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goauthentik
Goauthentik authentik |
|
| Vendors & Products |
Goauthentik
Goauthentik authentik |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3. | |
| Title | authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T19:05:26.760Z
Reserved: 2026-04-30T16:44:48.378Z
Link: CVE-2026-42849
Updated: 2026-06-03T19:04:56.856Z
Status : Received
Published: 2026-06-02T21:16:27.670
Modified: 2026-06-02T21:16:27.670
Link: CVE-2026-42849
No data.
OpenCVE Enrichment
Updated: 2026-06-03T05:45:26Z