PT-2026-56532 · Authentik · Authentik

CVE-2026-57580

·

Published

2026-07-08

·

Updated

2026-08-24

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2026.2.6 authentik versions prior to 2026.5.5
Description An inbound SAML Source configured with non-default USERNAME LINK or EMAIL LINK user-matching modes interprets XML comments within a NameID differently than the identity provider's signed assertion. An attacker capable of modifying their account's NameID on the source identity provider can inject an XML comment to truncate the value processed by authentik to the text preceding the comment, while the signed assertion remains valid. This allows a crafted NameID to match a victim's username or email, binding the attacker's external identity to the victim's account and enabling full account takeover without requiring the victim's password or the identity provider's private key. The malicious link persists, allowing subsequent logins without the need for the XML comment. SAML Sources using the default unique-identifier matching mode and the outbound SAML Provider role are not affected.
Recommendations Update authentik to version 2026.2.6 or later. Update authentik to version 2026.5.5 or later. As a temporary mitigation, avoid using USERNAME LINK or EMAIL LINK user-matching modes for inbound SAML Sources.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2026-57580
CVE-2026-57580
GHSA-35V6-HV2G-6992

Affected Products

Authentik