{"schema_version":1,"title":"Goauthentik vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in Goauthentik: 0 in the last 7 days and 0 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-49448, was published on 2 June 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/goauthentik","json_url":"https://junglewise.ai/threats/vendors/goauthentik.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/goauthentik","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":10,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":9},"latest":[{"cve":"CVE-2026-49448","cvss":9.8,"slug":"cve-2026-49448-goauthentik-authentik-authentication-bypass-in-source-stage","title":"goauthentik authentik authentication bypass in Source stage","severity":"critical","exploited":false,"published_at":"2026-06-02T21:16:28.49+00:00","url":"https://junglewise.ai/threats/cve-2026-49448-goauthentik-authentik-authentication-bypass-in-source-stage"},{"cve":"CVE-2026-49443","cvss":8.8,"slug":"cve-2026-49443-goauthentik-authentik-improper-authentication-in-source","title":"goauthentik authentik improper authentication in Source Connections","severity":"high","exploited":false,"published_at":"2026-06-02T21:16:28.36+00:00","url":"https://junglewise.ai/threats/cve-2026-49443-goauthentik-authentik-improper-authentication-in-source"},{"cve":"CVE-2026-47201","cvss":8.5,"epss":0.0028,"slug":"cve-2026-47201-goauthentik-authentik-xml-signature-wrapping-in-saml-source-acs","title":"goauthentik authentik XML Signature Wrapping in SAML Source ACS","severity":"high","exploited":false,"published_at":"2026-06-02T21:16:27.94+00:00","url":"https://junglewise.ai/threats/cve-2026-47201-goauthentik-authentik-xml-signature-wrapping-in-saml-source-acs"},{"cve":"CVE-2026-42849","cvss":9.3,"slug":"cve-2026-42849-authentik-reflected-xss-in-simple-flow-executor-autosubmitstage","title":"authentik reflected XSS in Simple Flow Executor AutosubmitStage","severity":"critical","exploited":false,"published_at":"2026-06-02T21:16:27.67+00:00","url":"https://junglewise.ai/threats/cve-2026-42849-authentik-reflected-xss-in-simple-flow-executor-autosubmitstage"},{"cve":"CVE-2026-41569","cvss":6.9,"slug":"cve-2026-41569-authentik-ws-federation-origin-bypass-in-wreply-parameter","title":"authentik WS-Federation origin bypass in wreply parameter","severity":"info","exploited":false,"published_at":"2026-06-02T21:16:27.537+00:00","url":"https://junglewise.ai/threats/cve-2026-41569-authentik-ws-federation-origin-bypass-in-wreply-parameter"},{"cve":"CVE-2026-41577","cvss":6.9,"slug":"cve-2026-41577-goauthentik-authentik-insufficient-saml-assertion-validation-in","title":"goauthentik authentik insufficient SAML assertion validation in ResponseProcessor","severity":"info","exploited":false,"published_at":"2026-06-02T20:16:36.117+00:00","url":"https://junglewise.ai/threats/cve-2026-41577-goauthentik-authentik-insufficient-saml-assertion-validation-in"},{"cve":"CVE-2026-40172","cvss":8.1,"epss":0.0054,"slug":"cve-2026-40172-goauthentik-authentik-privilege-escalation-in-user-patch-api","title":"goauthentik authentik privilege escalation in User PATCH API","severity":"high","exploited":false,"published_at":"2026-05-22T19:17:03.893+00:00","url":"https://junglewise.ai/threats/cve-2026-40172-goauthentik-authentik-privilege-escalation-in-user-patch-api"},{"cve":"CVE-2026-40166","cvss":7.1,"epss":0.0046,"slug":"cve-2026-40166-goauthentik-authentik-information-disclosure-in-oauth2-api","title":"goauthentik authentik information disclosure in OAuth2 API","severity":"info","exploited":false,"published_at":"2026-05-22T19:17:03.763+00:00","url":"https://junglewise.ai/threats/cve-2026-40166-goauthentik-authentik-information-disclosure-in-oauth2-api"},{"cve":"CVE-2026-40165","cvss":8.7,"slug":"cve-2026-40165-goauthentik-authentik-authentication-bypass-via-saml-nameid-xml","title":"goauthentik authentik authentication bypass via SAML NameID XML comment injection","severity":"high","exploited":false,"published_at":"2026-05-21T00:16:28.29+00:00","url":"https://junglewise.ai/threats/cve-2026-40165-goauthentik-authentik-authentication-bypass-via-saml-nameid-xml"},{"cve":"CVE-2023-39522","cvss":5.3,"epss":0.0062,"slug":"cve-2023-39522-goauthentik-username-enumeration-in-recovery-flow","title":"goauthentik username enumeration in recovery flow","severity":"medium","exploited":false,"published_at":"2023-08-29T23:34:51+00:00","url":"https://junglewise.ai/threats/cve-2023-39522-goauthentik-username-enumeration-in-recovery-flow"}],"vendor":{"hub":true,"name":"Goauthentik","slug":"goauthentik","homepage":"https://goauthentik.io/","description":"goauthentik is the developer of authentik, an open-source identity provider focused on flexibility and integration.","url":"https://junglewise.ai/threats/vendors/goauthentik"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-49448","cvss":9.8,"slug":"cve-2026-49448-goauthentik-authentik-authentication-bypass-in-source-stage","title":"goauthentik authentik authentication bypass in Source stage","severity":"critical","exploited":false,"published_at":"2026-06-02T21:16:28.49+00:00","url":"https://junglewise.ai/threats/cve-2026-49448-goauthentik-authentik-authentication-bypass-in-source-stage"},{"cve":"CVE-2026-42849","cvss":9.3,"slug":"cve-2026-42849-authentik-reflected-xss-in-simple-flow-executor-autosubmitstage","title":"authentik reflected XSS in Simple Flow Executor AutosubmitStage","severity":"critical","exploited":false,"published_at":"2026-06-02T21:16:27.67+00:00","url":"https://junglewise.ai/threats/cve-2026-42849-authentik-reflected-xss-in-simple-flow-executor-autosubmitstage"},{"cve":"CVE-2026-49443","cvss":8.8,"slug":"cve-2026-49443-goauthentik-authentik-improper-authentication-in-source","title":"goauthentik authentik improper authentication in Source Connections","severity":"high","exploited":false,"published_at":"2026-06-02T21:16:28.36+00:00","url":"https://junglewise.ai/threats/cve-2026-49443-goauthentik-authentik-improper-authentication-in-source"},{"cve":"CVE-2026-40165","cvss":8.7,"slug":"cve-2026-40165-goauthentik-authentik-authentication-bypass-via-saml-nameid-xml","title":"goauthentik authentik authentication bypass via SAML NameID XML comment injection","severity":"high","exploited":false,"published_at":"2026-05-21T00:16:28.29+00:00","url":"https://junglewise.ai/threats/cve-2026-40165-goauthentik-authentik-authentication-bypass-via-saml-nameid-xml"},{"cve":"CVE-2026-47201","cvss":8.5,"epss":0.0028,"slug":"cve-2026-47201-goauthentik-authentik-xml-signature-wrapping-in-saml-source-acs","title":"goauthentik authentik XML Signature Wrapping in SAML Source ACS","severity":"high","exploited":false,"published_at":"2026-06-02T21:16:27.94+00:00","url":"https://junglewise.ai/threats/cve-2026-47201-goauthentik-authentik-xml-signature-wrapping-in-saml-source-acs"},{"cve":"CVE-2026-40172","cvss":8.1,"epss":0.0054,"slug":"cve-2026-40172-goauthentik-authentik-privilege-escalation-in-user-patch-api","title":"goauthentik authentik privilege escalation in User PATCH API","severity":"high","exploited":false,"published_at":"2026-05-22T19:17:03.893+00:00","url":"https://junglewise.ai/threats/cve-2026-40172-goauthentik-authentik-privilege-escalation-in-user-patch-api"},{"cve":"CVE-2023-39522","cvss":5.3,"epss":0.0062,"slug":"cve-2023-39522-goauthentik-username-enumeration-in-recovery-flow","title":"goauthentik username enumeration in recovery flow","severity":"medium","exploited":false,"published_at":"2023-08-29T23:34:51+00:00","url":"https://junglewise.ai/threats/cve-2023-39522-goauthentik-username-enumeration-in-recovery-flow"},{"cve":"CVE-2026-40166","cvss":7.1,"epss":0.0046,"slug":"cve-2026-40166-goauthentik-authentik-information-disclosure-in-oauth2-api","title":"goauthentik authentik information disclosure in OAuth2 API","severity":"info","exploited":false,"published_at":"2026-05-22T19:17:03.763+00:00","url":"https://junglewise.ai/threats/cve-2026-40166-goauthentik-authentik-information-disclosure-in-oauth2-api"},{"cve":"CVE-2026-41569","cvss":6.9,"slug":"cve-2026-41569-authentik-ws-federation-origin-bypass-in-wreply-parameter","title":"authentik WS-Federation origin bypass in wreply parameter","severity":"info","exploited":false,"published_at":"2026-06-02T21:16:27.537+00:00","url":"https://junglewise.ai/threats/cve-2026-41569-authentik-ws-federation-origin-bypass-in-wreply-parameter"},{"cve":"CVE-2026-41577","cvss":6.9,"slug":"cve-2026-41577-goauthentik-authentik-insufficient-saml-assertion-validation-in","title":"goauthentik authentik insufficient SAML assertion validation in ResponseProcessor","severity":"info","exploited":false,"published_at":"2026-06-02T20:16:36.117+00:00","url":"https://junglewise.ai/threats/cve-2026-41577-goauthentik-authentik-insufficient-saml-assertion-validation-in"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"Goauthentik Authentik","slug":"authentik","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/authentik"}]}