Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:goauthentik:authentik:*:*:*:*:*:*:*:* |
Wed, 03 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goauthentik
Goauthentik authentik |
|
| Vendors & Products |
Goauthentik
Goauthentik authentik |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1. | |
| Title | authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T13:59:41.215Z
Reserved: 2026-05-30T02:43:33.106Z
Link: CVE-2026-49443
Updated: 2026-06-03T13:59:33.453Z
Status : Analyzed
Published: 2026-06-02T21:16:28.360
Modified: 2026-06-04T20:16:00.440
Link: CVE-2026-49443
No data.
OpenCVE Enrichment
Updated: 2026-06-03T04:30:05Z