LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-40165

Published
CVSS8.7
Severityhigh
WeaknessCWE-91
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Description

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick authentik into only seeing a part of the NameID value, potentially allowing an attacker to gain access to other accounts. This issue could be exploited on an authentik instance with a SAML Source, where the attacker had an account on the SAML Source and the ability to modify their NameID value (commonly username or E-mail), and XML Signing was enabled. The attacker could modify the

References

← Back to the CVE Tracker

Our coverage of CVE-2026-40165

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-40165.