CVE-2026-40172Disclosure

MEDIUMCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring enable_group_superuser, leading to privilege escalation. This bypasses the stricter permission model enforced in group-management paths and enables delegated user-management permissions to escalate target users to administrator-equivalent privilege. Users with permissions to update groups or permissions to update users are able to add themselves or other users they have permissions on to users which have superuser permissions. This issue has been fixed in versions 22025.12.5 and 2026.2.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-23); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-23: 3Mentions · 2026-05-25: 1Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-05-23: 1Technical Details · 2026-05-23: 2Technical Details · 2026-05-25: 105-2305-25
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-233
Active Exploitation1Disclosure2
2026-05-251
Disclosure1
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    Is your self-hosted network actually secure? A brand new CVE-2026-40172 just dropped for Authentik, targeting Single Sign-On (SSO) gateways. Don't let hackers compromise your Proxmox cluster. #infosec #devops #proxmox #valtersit #CVE #CVEAlert #devsecops #hackers https://t.co/fV1WfwVudD

    Post summary

    An alert announces the new CVE‑2026‑40172 for Authentik SSO gateways, with no proof‑of‑concept, exploit code, or patch details yet.

    11010297
    904 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40172 authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a calle… https://www.cve.org/CVERecord?id=CVE-2026-40172 ----- Traducción: CVE-2026-40172 aut… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-40172 affecting certain authentik releases, linking to the CVE record, but does not mention PoC, exploit, active use, or patch details.

    0000044
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40172 authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a calle… https://www.cve.org/CVERecord?id=CVE-2026-40172

    Post summary

    The text announces a new vulnerability in authentik, indicates affected versions and implies a fix, but lacks evidence of exploitation or a PoC.

    00000219
    57.5K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting goauthentik authentik (CVE-2026-40172) https://vuldb.com/vuln/365267/cti

    Post summary

    The tweet indicates observable increase in activities targeting the CVE‑2026‑40172 vulnerability and provides a link to a VULDB entry, suggesting potential exploitation in the wild.

    0000061
    2.2K followersView on X

Explore more