SAML Source User-Matching Mode Vulnerability in Authentik Identity Provider
CVE-2026-57580

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-57580?

An issue exists in Authentik, an open-source identity provider, where specific configurations of inbound SAML Sources enable a malicious account to exploit the user-matching mode. The vulnerability arises when an attacker injects an XML comment within the NameID, causing the identity provider to truncate the recognized value to a malicious entity's desired format. As a result, the attacker can link their external identity to the victim's existing profile without needing the victim's password, facilitating an unauthorized account takeover. This risk is not present for configurations using the default unique-identifier matching mode, and it has been rectified in the updates released as versions 2026.2.6 and 2026.5.5.

Affected Version(s)

authentik < 2026.2.6 < 2026.2.6

authentik >= 2026.5.0, < 2026.5.5 < 2026.5.0, 2026.5.5

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.