Cross-site scripting in authentik - CVE-2026-42849
Published: May 12, 2026
authentik
Detailed vulnerability description
The vulnerability allows a remote attacker to perform cross-site scripting and hijack the session.
The vulnerability exists due to cross-site scripting in the AutosubmitStage in the SFE (Simple Flow Executor) when handling malicious input values in OAuth2 provider parameters. A remote attacker can supply a crafted redirect_uri or state value to perform cross-site scripting and hijack the session.
User interaction is required, and exploitation is possible when an OAuth2 provider is configured.