PT-2026-42826 · Goauthentik · Authentik

Published

2026-05-22

·

Updated

2026-05-22

·

CVE-2026-40166

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client secret of confidential OAuth2 providers they have previously authenticated against, exposing sensitive information to users without the correct permissions. This logic is GET /api/v3/oauth2/access tokens/. The API response includes a nested provider object containing client id and client secret for providers configured with client type: confidential, which should not be accessible to low-privilege users. This issue has been fixed in versions 2025.12.5 and 2026.2.3.

Fix

Information Disclosure

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-40166

Affected Products

Authentik