CVE-2026-40165: authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation

Published May 20, 2026
·
Updated

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick authentik into only seeing a part of the NameID value, potentially allowing an attacker to gain access to other accounts. This issue could be exploited on an authentik instance with a SAML Source, where the attacker had an account on the SAML Source and the ability to modify their NameID value (commonly username or E-mail), and XML Signing was enabled. The attacker could modify the SAML assertion given to authentik by injecting a comment within the NameID value, which effectively truncated the NameID value to the snippet before the comment, and gave the attacker access to any user account. This issue has been fixed in versions 2025.12.5 and 2026.2.3.

Affected Software

1 affected component
Authentik Authentik<=2025.12.4, >=2026.2.0-rc1<=2026.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade authentik to a version that resolves this vulnerability.

    Fixed in 2025.12.5
  2. Upgrade

    Upgrade authentik to a version that resolves this vulnerability.

    Fixed in 2026.2.3

Event History

May 20, 2026
CVE Published
via MITRE·11:35 PM
Data Sourced
via MITRE·11:35 PM
DescriptionSeverityWeakness
May 21, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-40165?

The severity of CVE-2026-40165 is classified as high due to its ability to allow authentication bypass.

2

How do I fix CVE-2026-40165?

To fix CVE-2026-40165, upgrade authentik to version 2025.12.5 or later, or to versions beyond 2026.2.2.

3

What software is affected by CVE-2026-40165?

CVE-2026-40165 affects authentik versions 2025.12.4 and prior, as well as versions 2026.2.0-rc1 through 2026.2.2.

4

What is the nature of the vulnerability in CVE-2026-40165?

CVE-2026-40165 involves SAML NameID XML Comment Injection, which enables authentication bypass via identifier truncation.

5

Are there any workarounds for CVE-2026-40165?

There are no known effective workarounds for CVE-2026-40165; the recommended action is to upgrade to a fixed version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203