CVE-2026-49448 - authentik: SourceStage bypass via empty POST
CVE ID :CVE-2026-49448 Published : June 2, 2026, 9:16 p.m. | 1 hour, 57 minutes ago Description :authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in...