Junglewise Threat Intelligence

CVE-2026-49443: goauthentik authentik improper authentication in Source Connections

CVE-2026-49443 · Severity: high · CVSS 8.8 · Published 2026-06-02

Technologies: Goauthentik Authentik. Vendors: Goauthentik.

Executive brief

authentik is an open-source identity provider used to manage user authentication and access control. A security flaw allows an attacker with limited permissions to modify account connection settings, enabling them to link their own credentials to a high-privilege account like an administrator. This could result in a complete takeover of the identity system and unauthorized access to all connected corporate applications.

Technical details

An improper authentication vulnerability exists in authentik due to the UserSourceConnectionSerializer and GroupSourceConnectionSerializer fields not being marked as read-only in the API. An attacker with 'add' or 'change' permissions for UserSourceConnection or GroupSourceConnection objects can modify the 'user' or 'group' fields via the API. By remapping a source connection identifier they control to a target victim's account (such as an administrator), the attacker can bypass standard authentication boundaries and log in as that user. This issue is patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.

Affected products

  • goauthentik authentik < 2025.12.6, < 2026.2.4, < 2026.5.1

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-06-02: disclosed: CVE published to NVD

References

Related threats