Authentication Bypass Vulnerability in Authentik Identity Provider by GoAuthentik
CVE-2026-40165

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-40165?

Authentik, an open-source identity provider, experienced a vulnerability allowing authentication bypass through SAML NameID XML Comment Injection. Attackers could manipulate the NameID value extracted from a SAML assertion, potentially gaining unauthorized access to other user accounts. This exploitation required that an attacker had an account with a SAML Source and the capability to modify their NameID value. By injecting a comment into the NameID, the attacker could truncate the visible NameID value, thus accessing accounts without authorization. The issue is resolved in versions 2025.12.5 and 2026.2.3.

Affected Version(s)

authentik < 2025.12.5 < 2025.12.5

authentik >= 2026.2.0-rc1, < 2026.2.3 < 2026.2.0-rc1, 2026.2.3

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.