Authentication Bypass Vulnerability in Authentik Identity Provider by GoAuthentik
CVE-2026-40165
8.7HIGH
What is CVE-2026-40165?
Authentik, an open-source identity provider, experienced a vulnerability allowing authentication bypass through SAML NameID XML Comment Injection. Attackers could manipulate the NameID value extracted from a SAML assertion, potentially gaining unauthorized access to other user accounts. This exploitation required that an attacker had an account with a SAML Source and the capability to modify their NameID value. By injecting a comment into the NameID, the attacker could truncate the visible NameID value, thus accessing accounts without authorization. The issue is resolved in versions 2025.12.5 and 2026.2.3.
Affected Version(s)
authentik < 2025.12.5 < 2025.12.5
authentik >= 2026.2.0-rc1, < 2026.2.3 < 2026.2.0-rc1, 2026.2.3
