What is CVE-2026-57580?
The CVE-2026-57580 vulnerability in the open-source identity provider authentik stems from improper handling of XML comments within SAML NameID when using non-default USERNAME_LINK or EMAIL_LINK matching modes. An attacker could exploit this to bypass signed assertion validation, potentially gaining unauthorized access by manipulating inbound SAML authentication. Upgrading to versions 2026.2.6 or 2026.5.5 is strongly recommended to mitigate the risk.
Azərbaycanca: authentik açıq mənbəli identiklik təminatçısında aşkarlanan CVE-2026-57580 zəifliyi, standart olmayan USERNAME_LINK və ya EMAIL_LINK rejimində konfiqurasiya edilmiş SAML mənbələrində XML şərhinin səhv şərh edilməsinə səbəb olur. Bu, hücumçuya imzalanmış təsdiq məlumatlarını manipulyasiya edərək icazəsiz giriş əldə etməyə imkan verə bilər. Təsirə məruz qalmamaq üçün 2026.2.6 və ya 2026.5.5 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
In which matching modes does the CVE-2026-57580 vulnerability occur in authentik?
This vulnerability only occurs in SAML sources configured with non-default USERNAME_LINK or EMAIL_LINK matching modes.
Which versions are recommended to upgrade to in order to mitigate CVE-2026-57580?
The recommended versions are 2026.2.6 or 2026.5.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.