Synced 17 Jun 2026 06:32 UTC Account
← authentik

authentik: 2025.10.4 2025.12.6

authentik · upgrade impact · Official site ↗

Fixed by upgrading to 2025.12.6 iVulnerabilities that affect 2025.10.4 but no longer affect 2025.12.6 — the security gain from this upgrade, by exploited status then exploitation probability.

Exploited first, then by exploitation probability (EPSS).

CVE-2026-42849 CRITICAL EPSS 0% ✓ cleared in 2025.12.6 CVE-2026-49448 CRITICAL EPSS 0% ✓ cleared in 2025.12.6 CVE-2026-47201 HIGH EPSS 0% ✓ cleared in 2025.12.6 CVE-2026-49443 HIGH EPSS 0% ✓ cleared in 2025.12.6 CVE-2026-41577 HIGH EPSS 0% ✓ cleared in 2025.12.6

Still open in 2025.12.6 iKnown vulnerabilities that affect 2025.12.6 too — upgrading to it does not clear these.

These affect 2025.12.6 as well — a later release may be needed.

CVE-2026-41569 MEDIUM EPSS 0% → fixed in 2026.2.3