CVE-2026-40166: authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/

Published May 22, 2026
·
Updated

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the clientsecret of confidential OAuth2 providers they have previously authenticated against, exposing sensitive information to users without the correct permissions. This logic is GET /api/v3/oauth2/accesstokens/. The API response includes a nested provider object containing clientid and clientsecret for providers configured with clienttype: confidential, which should not be accessible to low-privilege users. This issue has been fixed in versions 2025.12.5 and 2026.2.3.

Affected Software

1 affected component
Authentik Authentik<2025.12.5, >=2026.2.0-rc1<=2026.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade authentik to a version that resolves this vulnerability.

    Fixed in 2025.12.5
  2. Upgrade

    Upgrade authentik to a version that resolves this vulnerability.

    Fixed in 2026.2.3

Event History

May 22, 2026
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-40166?

CVE-2026-40166 has a risk score of 47, indicating a moderate level of severity.

2

How do I fix CVE-2026-40166?

To fix CVE-2026-40166, upgrade to Authentik version 2025.12.5 or 2026.2.3 or newer.

3

What type of vulnerability is CVE-2026-40166?

CVE-2026-40166 is classified as an information leakage vulnerability.

4

Who is affected by CVE-2026-40166?

Authenticated non-admin users of Authentik with OAuth2 access tokens are affected by CVE-2026-40166.

5

What can an attacker do with CVE-2026-40166?

An attacker can retrieve confidential OAuth client_secret information, potentially compromising OAuth2 providers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203