Executive brief
authentik is an open-source identity provider used to manage user authentication and access to applications. A security flaw allows standard, non-administrator users to view sensitive 'client secrets' for applications they have logged into. An attacker could use these stolen secrets to impersonate legitimate applications, potentially leading to unauthorized data access or further security breaches.
Technical details
An information disclosure vulnerability exists in the authentik API endpoint 'GET /api/v3/oauth2/access_tokens/'. The root cause is an authorization failure where the API response includes a nested provider object containing the 'client_id' and 'client_secret' for confidential OAuth2 providers. To exploit this, an attacker must be an authenticated non-admin user who has previously completed an OAuth2 flow against a confidential provider. Successful exploitation allows the attacker to retrieve the provider's secret, which could be used to facilitate unauthorized credential reuse. The issue is fixed in versions 2025.12.5 and 2026.2.3.
Affected products
- goauthentik authentik < 2025.12.5, >= 2026.2.0-rc1, < 2026.2.3
Timeline
- 2026-05-12: patched: Versions 2025.12.5 and 2026.2.3 released
- 2026-05-12: advisory: GitHub Security Advisory GHSA-hhpc-rqgm-pxj4 published
- 2026-05-22: disclosed: CVE-2026-40166 published to NVD