Authentication Bypass Vulnerability in Authentik Identity Provider
CVE-2026-49443
8.8HIGH
What is CVE-2026-49443?
Authentik, an open-source identity provider, contains a vulnerability that allows attackers to bypass authentication if they can modify a source connection and possess an account from one of the configured sources. This flaw enables unauthorized access to any account, leading to potential data breaches. Mitigations are available in Authentik versions 2025.12.6, 2026.2.4, and 2026.5.1, which address this flaw effectively.
Affected Version(s)
authentik < 2025.12.6 < 2025.12.6
authentik < 2026.2.4 < 2026.2.4
authentik < 2026.5.1 < 2026.5.1
