SAML Source User-Matching Mode Vulnerability in Authentik Identity Provider
CVE-2026-57580
What is CVE-2026-57580?
An issue exists in Authentik, an open-source identity provider, where specific configurations of inbound SAML Sources enable a malicious account to exploit the user-matching mode. The vulnerability arises when an attacker injects an XML comment within the NameID, causing the identity provider to truncate the recognized value to a malicious entity's desired format. As a result, the attacker can link their external identity to the victim's existing profile without needing the victim's password, facilitating an unauthorized account takeover. This risk is not present for configurations using the default unique-identifier matching mode, and it has been rectified in the updates released as versions 2026.2.6 and 2026.5.5.
Affected Version(s)
authentik < 2026.2.6 < 2026.2.6
authentik >= 2026.5.0, < 2026.5.5 < 2026.5.0, 2026.5.5
