StatewardStateward
PlatformPricingComplianceVulnerabilitiesCase studiesDocsBlogAbout
enfr
Book a Demo / ContactGet started free
← All vulnerabilities
HIGHSupply chain

CVE-2026-47201

Go · goauthentik.io

Summary

authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user

References

  • https://github.com/goauthentik/authentik/security/advisories/GHSA-c3m2-jqmq-pvp3
  • https://nvd.nist.gov/vuln/detail/CVE-2026-47201
  • https://github.com/goauthentik/authentik/commit/a370d76d23c7de0fceed064ca322e33e6ebf0119
SourceStateward
Severityhigh
EPSS0.3% (p16)
Also known asGHSA-c3m2-jqmq-pvp3, BIT-authentik-2026-47201
Added2026-05-29

Is your project exposed to this? Stateward checks every dependency on every pull request, and flags it only if your code actually reaches it.

Check my repo
Summarize with
ChatGPTClaudePerplexity

Related vulnerabilities

All Supply chain →
  • HIGHCVE-2026-52801

    Gogs has the ability to import local repositories via Mirror Settings

  • HIGHCVE-2026-52800

    Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

  • HIGHCVE-2026-52799

    Gogs Missing Authorization in Attachment Download

  • HIGHCVE-2026-52798

    Gogs has Stored XSS in `.ipynb` Preview

  • MEDIUMCVE-2026-50179

    @actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

  • HIGHCVE-2026-54353

    @budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

StatewardStateward

Autonomous cybersecurity for your entire codebase.

A venture of Yggdrasil Digital.

Product

  • Platform
  • What we detect
  • How we protect you
  • Pricing
  • Compliance
  • Vulnerabilities
  • Blog
  • Get started free

Resources

  • Breach breakdowns
  • Merge-induced flaws
  • Docs
  • Sample finding
  • Glossary
  • Compare
  • Threat feed API ↗

Company

  • About
  • Yggdrasil Digital ↗

Legal

  • Legal notice
  • Terms of Use
  • Terms of Sale
  • Privacy
  • Cookies
  • DPA

Connect

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Threat feed (RSS) ↗
  • hello@stateward.com

Stateward provides automated security analysis and does not guarantee detection of all vulnerabilities. It is designed to support, not replace, sound security practices and human judgement.

© 2026 Stateward. All rights reserved.A Yggdrasil Digital venture