A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-49443

CVE-2026-49443: authentik Auth Bypass Vulnerability

CVE-2026-49443 is an authentication bypass flaw in authentik identity provider that allows attackers to log into any account by exploiting source connections. This article covers technical details, affected versions, and patches.

Published: June 4, 2026

CVE-2026-49443 Overview

CVE-2026-49443 is an authentication bypass vulnerability in authentik, an open-source identity provider. An attacker with the ability to modify a source connection and an account in one of the configured sources can log into any account on the affected instance. The flaw is tracked under CWE-287: Improper Authentication and affects versions prior to 2025.12.6, 2026.2.4, and 2026.5.1. The maintainers have released patched versions addressing the issue.

Critical Impact

An authenticated attacker with source-modification privileges can authenticate as any user, including administrators, by abusing federated source connection logic.

Affected Products

  • authentik versions prior to 2025.12.6 (2025.12.x branch)
  • authentik versions prior to 2026.2.4 (2026.2.x branch)
  • authentik versions prior to 2026.5.1 (2026.5.x branch)

Discovery Timeline

  • 2026-06-02 - CVE-2026-49443 published to NVD
  • 2026-06-03 - Last updated in NVD database

Technical Details for CVE-2026-49443

Vulnerability Analysis

The vulnerability lives in how authentik links externally federated identities from configured sources to internal user accounts. When an attacker can modify a source connection and controls an account in one of the configured sources, the linking logic fails to enforce a trustworthy binding between the source identity and the target internal account. The result is that the attacker can pivot through the federated source and complete authentication as an arbitrary user.

Because authentik is commonly deployed as a single sign-on (SSO) gateway, the bypass extends across every downstream application protected by the identity provider. Successful exploitation yields full account takeover, including administrative accounts when an admin account is targeted. The CWE-287 classification reflects an authentication mechanism that accepts attacker-influenced data as proof of identity.

Root Cause

The root cause is improper validation during source-to-user linkage. The flow permits an actor with write access to a source connection and a controlled identity in that source to alter the linkage so that the controlled source identity resolves to a victim user. Authentication then succeeds against the victim account without the victim's credentials or consent.

Attack Vector

The attack is conducted over the network and requires low privileges — specifically, the ability to change a source connection within authentik plus an account in one of the configured sources. No user interaction is required. The attacker first manipulates the source configuration or linkage, authenticates through the federated source using their controlled identity, and is granted a session bound to the chosen victim account.

No public proof-of-concept exploit is available at publication time. Refer to the GitHub Security Advisory GHSA-wr38-7xg8-fqxr for vendor-provided technical detail.

Detection Methods for CVE-2026-49443

Indicators of Compromise

  • Unexpected modifications to source connection objects in authentik audit logs, particularly to OAuth, SAML, or LDAP source configurations.
  • Successful logins to privileged accounts immediately preceded by source configuration changes performed by non-administrative operators.
  • New or altered user-to-source identity bindings that do not correspond to legitimate provisioning activity.

Detection Strategies

  • Review authentik audit events for model_updated actions against source objects and correlate with subsequent successful authentication events for high-value accounts.
  • Alert on logins where the authenticating source identity was created, modified, or relinked within a short window prior to the login.
  • Hunt for sessions where the federated source subject identifier does not match the historical binding for the target user account.

Monitoring Recommendations

  • Forward authentik audit and event logs to a centralized SIEM and retain them for incident reconstruction.
  • Monitor administrative API endpoints under /api/v3/sources/ for unauthorized modifications.
  • Track privileged role assignments and password-less authentications originating from federated sources for anomalous patterns.

How to Mitigate CVE-2026-49443

Immediate Actions Required

  • Upgrade authentik to 2025.12.6, 2026.2.4, or 2026.5.1 depending on the deployed release branch.
  • Audit which operators hold permissions to modify source connections and revoke access from accounts that do not require it.
  • Review recent source configuration changes and recent administrative logins for signs of exploitation prior to patching.

Patch Information

The authentik maintainers have released fixed versions 2025.12.6, 2026.2.4, and 2026.5.1. Patch details and remediation guidance are provided in the GitHub Security Advisory GHSA-wr38-7xg8-fqxr.

Workarounds

  • Restrict the authentik Admins group and any custom roles that grant write access to source objects until the upgrade is complete.
  • Temporarily disable non-essential federated sources to reduce the available attack surface.
  • Require multi-factor authentication on administrative accounts so that a source-based bypass alone does not yield full takeover of privileged sessions.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechAuthentik

  • SeverityHIGH

  • CVSS Score8.8

  • EPSS Probability0.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-287
  • Technical References
  • GitHub Security Advisory
  • Related CVEs
  • CVE-2026-49448: authentik Auth Bypass Vulnerability

  • CVE-2026-47201: authentik Auth Bypass Vulnerability

  • CVE-2026-41569: authentik Auth Bypass Vulnerability

  • CVE-2026-41577: authentik SAML Auth Bypass Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English