Executive brief
authentik is an open-source identity provider used to manage user authentication and authorization for organizations. A security flaw allows users with limited administrative permissions to grant themselves or others full administrator (superuser) status. This could lead to an unauthorized takeover of the entire identity management system, allowing an attacker to modify security policies or access sensitive user data.
Technical details
A privilege escalation vulnerability exists in the authentik UserSerializer component. The 'PATCH /api/v3/core/users/{pk}/' API endpoint fails to properly enforce the 'enable_group_superuser' requirement when updating user group memberships. An authenticated attacker with 'change_user' permissions can bypass the strict permission model typically enforced in group-management paths. By submitting a crafted PATCH request, the attacker can assign themselves or other users to groups with 'is_superuser=True', effectively gaining full administrative control. The vulnerability is resolved in versions 2025.12.5 and 2026.2.3.
Affected products
- goauthentik authentik < 2025.12.5, >= 2026.2.0-rc1, < 2026.2.3
Timeline
- 2026-05-12: patched: Versions 2025.12.5 and 2026.2.3 released
- 2026-05-12: advisory: GitHub Security Advisory GHSA-h6x7-hjjc-wjc9 published
- 2026-05-22: disclosed: CVE-2026-40172 published to NVD