vulns.co
/
GKData.io MCP

authentik · 1 min read

authentik: source-mapping edits carry identity-rebinding authority

CVE-2026-49443 concerns writable identity-mapping fields in API serializers. Delegated connection-management authority could alter which local user or group a source identity represented. The maintainer reports victim-account authentication; its example addresses user mappings, while the impact statement also covers groups.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial reasoning: permission to maintain an integration object does not establish permission to reassign the identity it authenticates. Treat identity bindings as security-sensitive relationships, restrict writable fields, and separately authorize any supported reassignment. The advisory lists patched versions 2025.12.6, 2026.2.4 and 2026.5.1.

Before reading

  • Identity-provider integration and authorization concepts

Context and limits

  • The described user case requires both an account at a configured identity source and delegated permission to add or change source connections. Ordinary authentication alone is insufficient.
  • rissson published the maintainer advisory; no separate reporter is identified. Group consequences are described more broadly than the user-focused example; no independent reproduction is claimed.
  • Patch release dates are not established by the advisory. Publication and educational edition metadata must not substitute for software chronology. No individual award is established.

Sources and provenance

  1. UserSourceConnection.user and GroupSourceConnection.group are changeable through the API authentik · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software