PT-2026-56532 · Authentik · Authentik
CVE-2026-57580
·
Published
2026-07-08
·
Updated
2026-08-24
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
authentik versions prior to 2026.2.6
authentik versions prior to 2026.5.5
Description
An inbound SAML Source configured with non-default
USERNAME LINK or EMAIL LINK user-matching modes interprets XML comments within a NameID differently than the identity provider's signed assertion. An attacker capable of modifying their account's NameID on the source identity provider can inject an XML comment to truncate the value processed by authentik to the text preceding the comment, while the signed assertion remains valid. This allows a crafted NameID to match a victim's username or email, binding the attacker's external identity to the victim's account and enabling full account takeover without requiring the victim's password or the identity provider's private key. The malicious link persists, allowing subsequent logins without the need for the XML comment. SAML Sources using the default unique-identifier matching mode and the outbound SAML Provider role are not affected.Recommendations
Update authentik to version 2026.2.6 or later.
Update authentik to version 2026.5.5 or later.
As a temporary mitigation, avoid using
USERNAME LINK or EMAIL LINK user-matching modes for inbound SAML Sources.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Authentik