CVE-2026-42849: authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
authentik (SFE AutosubmitStage)to a version that resolves this vulnerability.Fixed in 2025.12.5 - Upgrade
Upgrade
authentik (SFE AutosubmitStage)to a version that resolves this vulnerability.Fixed in 2026.2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42849?
CVE-2026-42849 has a critical severity rating of 9.3.
What is CVE-2026-42849?
CVE-2026-42849 is a reflected XSS vulnerability in the SFE AutosubmitStage of the authentik identity provider that allows for IDP account takeover.
How do I fix CVE-2026-42849?
To fix CVE-2026-42849, upgrade to authentik versions 2025.12.5 or 2026.2.3 or later.
What impact does CVE-2026-42849 have?
The impact of CVE-2026-42849 includes potential account takeover through exploitation of the reflected XSS vulnerability.
Who is affected by CVE-2026-42849?
Users of authentik versions prior to 2025.12.5 and 2026.2.3 are affected by CVE-2026-42849.