Threat Advisory

Claude AI Discovers SAML Flaw in Authentik Enabling Account Hijacking

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-57580 with a CVSS score of 9.4 is a vulnerability that allows an attacker to use an XML comment inside a SAML NameID value, which can link an attacker-controlled external identity to the victim’s account, creating a persistent path to account takeover. The flaw affects Authentik, an open-source identity provider, and was discovered using an AI-assisted testing harness built around Claude Opus. The vulnerability is caused by inconsistent parser behavior in XML signature processing and allows attackers to bypass authentication and take over user accounts. It can be exploited before authentication and involves SAML signature wrapping techniques. The research also uncovered weaknesses beyond standard SAML login responses, including signature validation bypasses in authentication requests, attribute queries, and logout operations that can enable information disclosure or arbitrary user logouts.

RECOMMENDATIONS:

  • We recommend you to update Authentik to below version:
  • https://github.com/goauthentik/authentik/releases

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-57580 with a CVSS score of 9.4 is a vulnerability that allows an attacker to use an XML comment inside a SAML NameID value, which can link an attacker-controlled external identity to the victim’s account, creating a persistent path to account takeover. The flaw affects Authentik, an open-source identity provider, and was discovered using an AI-assisted testing harness built around Claude Opus. The vulnerability is caused by inconsistent parser behavior in XML signature processing and allows attackers to bypass authentication and take over user accounts. It can be exploited before authentication and involves SAML signature wrapping techniques. The research also uncovered weaknesses beyond standard SAML login responses, including signature validation bypasses in authentication requests, attribute queries, and logout operations that can enable information disclosure or arbitrary user logouts.

RECOMMENDATIONS:

  • We recommend you to update Authentik to below version:
  • https://github.com/goauthentik/authentik/releases

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu