Incorrect authorization in authentik - CVE-2026-40166

 

Incorrect authorization in authentik - CVE-2026-40166

Published: May 12, 2026


Vulnerability identifier: #VU131250
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40166
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /api/v3/oauth2/access_tokens/ endpoint when handling authenticated GET requests for OAuth2 access tokens. A remote user can retrieve an access token object containing a nested provider object with client_secret values to disclose sensitive information.

Exposure is limited to confidential OAuth2 providers the user has previously authenticated against and for which the user has at least one access token.


Affected software

authentik

How to mitigate CVE-2026-40166

Install security update from vendor's website.

authentik - addressed in versions 2025.12.5, 2026.2.3

External References

Related Security Bulletins