Junglewise Threat Intelligence

CVE-2026-40166: goauthentik authentik information disclosure in OAuth2 API

CVE-2026-40166 · Severity: info · CVSS 7.1 · Published 2026-05-22

Technologies: Goauthentik Authentik. Vendors: Goauthentik.

Executive brief

authentik is an open-source identity provider used to manage user authentication and access to applications. A security flaw allows standard, non-administrator users to view sensitive 'client secrets' for applications they have logged into. An attacker could use these stolen secrets to impersonate legitimate applications, potentially leading to unauthorized data access or further security breaches.

Technical details

An information disclosure vulnerability exists in the authentik API endpoint 'GET /api/v3/oauth2/access_tokens/'. The root cause is an authorization failure where the API response includes a nested provider object containing the 'client_id' and 'client_secret' for confidential OAuth2 providers. To exploit this, an attacker must be an authenticated non-admin user who has previously completed an OAuth2 flow against a confidential provider. Successful exploitation allows the attacker to retrieve the provider's secret, which could be used to facilitate unauthorized credential reuse. The issue is fixed in versions 2025.12.5 and 2026.2.3.

Affected products

  • goauthentik authentik < 2025.12.5, >= 2026.2.0-rc1, < 2026.2.3

Timeline

  • 2026-05-12: patched: Versions 2025.12.5 and 2026.2.3 released
  • 2026-05-12: advisory: GitHub Security Advisory GHSA-hhpc-rqgm-pxj4 published
  • 2026-05-22: disclosed: CVE-2026-40166 published to NVD

References

Related threats