CVE-2026-40172 is a privilege-escalation vulnerability in authentik, the open-source identity provider. In versions prior to 2025.12.5 and in 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API permits a caller with change_user permission on a target user to assign arbitrary groups via UserSerializer. This includes assigning groups marked with is_superuser=true without enforcing the enable_group_superuser restriction. The flaw bypasses the stricter authorization model applied in group-management code paths, allowing user-update functionality to be abused to grant administrator-equivalent privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains a standalone Python 3 proof of concept, a detailed Markdown vulnerability write-up, and an MIT license. CVE-2026-94609.py uses the requests library and a bearer API token to interact with authentik's /api/v3 Core API. It discovers the token owner, enumerates or resolves groups, resolves an optional victim user, retrieves current group membership, and PATCHes an existing is_superuser=true group's users field. The intended vulnerable condition is that authentik accepts this change when the caller has only authentik_core.add_user_to_group, without enforcing authentik_core.enable_group_superuser. Successful exploitation promotes the added account to authentik superuser. The script also supports non-mutating group/user inspection via --check-only and superuser-group enumeration via --list-groups. README.md documents affected releases through 2026.2.6, 2026.5.6, and 2026.8.1, with fixes in 2026.2.7, 2026.5.7, and 2026.8.2. No hard-coded victim infrastructure, callback host, or external command execution is present; the target base URL and API token are supplied by the operator.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.