CVE-2026-40165
authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick authentik into only seeing a part of the NameID value, potentially allowing an attacker to gain access to other accounts.
Leer descripción completaMostrar menos
This issue could be exploited on an authentik instance with a SAML Source, where the attacker had an account on the SAML Source and the ability to modify their NameID value (commonly username or E-mail), and XML Signing was enabled. The attacker could modify the SAML assertion given to authentik by injecting a comment within the NameID value, which effectively truncated the NameID value to the snippet before the comment, and gave the attacker access to any user account. This issue has been fixed in versions 2025.12.5 and 2026.2.3.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.68%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access85 % - Impacto secundario
T1556Modify Authentication Processdefense impairment · persistence · credential access70 %
SAML NameID XML comment injection (CWE-91) permite bypass de autenticación remota (AV:N, PR:N) con acceso a cuentas de usuario arbitrarias. SAML Source es servicio remoto expuesto; impacto primario es acceso fraudulento (T1078), secundario manipulación de autenticación (T1556).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-91, CWE-287, CWE-436
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-40165",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-40165",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-21T14:13:10.961177Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.7,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.8,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "goauthentik",
"product": "authentik",
"versions": [
{
"status": "affected",
"version": "< 2025.12.5"
},
{
"status": "affected",
"version": ">= 2026.2.0-rc1, < 2026.2.3"
}
]
}
]
}
],
"published": "2026-05-21T00:16:28.290",
"references": [
{
"url": "https://github.com/goauthentik/authentik/commit/47dec5c6b7fb4a62bfad2ae8bddf002bde7ba774",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/goauthentik/authentik/releases/tag/version%2F2025.12.5",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/goauthentik/authentik/security/advisories/GHSA-9wj8-xv4r-qwrp",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-91"
},
{
"lang": "en",
"value": "CWE-287"
},
{
"lang": "en",
"value": "CWE-436"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick authentik into only seeing a part of the NameID value, potentially allowing an attacker to gain access to other accounts. This issue could be exploited on an authentik instance with a SAML Source, where the attacker had an account on the SAML Source and the ability to modify their NameID value (commonly username or E-mail), and XML Signing was enabled. The attacker could modify the SAML assertion given to authentik by injecting a comment within the NameID value, which effectively truncated the NameID value to the snippet before the comment, and gave the attacker access to any user account. This issue has been fixed in versions 2025.12.5 and 2026.2.3."
},
{
"lang": "es",
"value": "authentik es un proveedor de identidad de código abierto. Las versiones 2025.12.4 y anteriores, y las versiones 2026.2.0-rc1 hasta la 2026.2.2 eran vulnerables a la omisión de autenticación a través de la inyección de comentarios XML en el NameID de SAML. Debido a cómo authentik extraía el valor NameID de una aserción SAML, era posible para un atacante engañar a authentik para que solo viera una parte del valor NameID, lo que potencialmente permitía a un atacante obtener acceso a otras cuentas. Este problema podía ser explotado en una instancia de authentik con una fuente SAML, donde el atacante tenía una cuenta en la fuente SAML y la capacidad de modificar su valor NameID (comúnmente nombre de usuario o correo electrónico), y la firma XML estaba habilitada. El atacante podía modificar la aserción SAML proporcionada a authentik inyectando un comentario dentro del valor NameID, lo que efectivamente truncaba el valor NameID al fragmento anterior al comentario, y le daba al atacante acceso a cualquier cuenta de usuario. Este problema ha sido solucionado en las versiones 2025.12.5 y 2026.2.3."
}
],
"lastModified": "2026-07-23T15:10:00.137",
"sourceIdentifier": "security-advisories@github.com"
}