The CVE record for CVE-2026-40172 was published on 2026-05-22T19:17:03.893Z and has not been modified since then. The NVD entry is currently Deferred. This high-severity vulnerability in Authentik open-source identity provider versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2 allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups w [truncated]
CVE-2026-40166 is a vulnerability in the authentik open-source identity provider. Authentik versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2 contain a flaw that allows authenticated non-admin users with at least one OAuth2 access token to retrieve the client_secret of confidential OAuth2 providers they have previously authenticated against. This issue exposes sensitive information to users wi [truncated]
CVE-2026-40165 is a high-severity authentication bypass in authentik’s SAML login flow. According to the CVE description, an attacker who already has an account on a SAML Source and can influence their NameID value may be able to inject an XML comment into the NameID field, causing authentik to read only part of the value and potentially map the login to another user’s account. The issue is fixed in authe [truncated]