PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40172 goauthentik CVE debrief

The CVE record for CVE-2026-40172 was published on 2026-05-22T19:17:03.893Z and has not been modified since then. The NVD entry is currently Deferred. This high-severity vulnerability in Authentik open-source identity provider versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2 allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring enable_group_superuser, leading to privilege escalation.

Vendor
goauthentik
Product
authentik
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Users with permissions to update groups or permissions to update users in Authentik open-source identity provider, particularly those managing user and group settings, should be aware of this vulnerability and take necessary actions to mitigate it.

Technical summary

CVE-2026-40172 is a high-severity vulnerability in Authentik open-source identity provider versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2. The vulnerability allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring enable_group_superuser, leading to privilege escalation. Users with permissions to update groups or permissions to update users are able to add themselves or other users they have permissions on to users which have superuser permissions.

Defensive priority

High

Recommended defensive actions

  • Review and update Authentik to version 2025.12.5 or 2026.2.3
  • Restrict permissions to update groups and users
  • Monitor user management activities
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability was fixed in versions 2025.12.5 and 2026.2.3. Users with permissions to update groups or permissions to update users are able to add themselves or other users they have permissions on to users which have superuser permissions. The CVE record was published on 2026-05-22T19:17:03.893Z and has not been modified since then. The NVD entry is currently Deferred.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T19:17:03.893Z and has not been modified since then. The NVD entry is currently Deferred.