Input validation error in authentik - CVE-2026-40165
Published: May 12, 2026
authentik
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to other user accounts.
The vulnerability exists due to improper input validation in the SAML NameID value extraction logic when processing a SAML assertion. A remote attacker can inject an XML comment into the NameID value to gain access to other user accounts.
Exploitation requires an authentik instance configured with a SAML Source, XML signing enabled, and an attacker-controlled account on the SAML Source that can modify its NameID value.