CVE-2026-40165
8.7goauthentik · authentik
A vulnerability in the authentik identity provider allows for improper authentication and XML injection, potentially leading to unauthorized access or security configuration conflicts.
Executive summary
A critical authentication vulnerability in authentik could allow unauthenticated attackers to bypass security controls and potentially compromise identity management.
Vulnerability
This vulnerability involves improper authentication (CWE-287), XML injection (CWE-91), and interpretation conflicts (CWE-436). The vulnerability is reachable by unauthenticated, remote attackers, creating a high risk of unauthorized access.
Business impact
As an identity provider, authentik holds the keys to organizational access; a compromise here can facilitate wide-scale unauthorized access to downstream applications. The CVSS score of 8.7 reflects the high severity of this flaw, as it permits remote, unauthenticated attackers to potentially hijack authentication flows or manipulate identity data.
Remediation
Immediate Action: Upgrade to authentik version 2025.12.5 or 2026.2.3 or later immediately to apply the security fixes.
Proactive Monitoring: Review authentication logs for anomalous login patterns, especially those involving malformed XML or unexpected identity provider behavior.
Compensating Controls: Utilize a Web Application Firewall (WAF) to filter malicious XML payloads and restrict access to the authentik administrative interface to trusted management networks.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The criticality of this vulnerability cannot be overstated given its role as an identity provider. Organizations must perform an immediate assessment of their authentik deployments and apply the provided patches to prevent potential identity-based attacks.