Description
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider-s signed assertion. An attacker with an account on the source identity provider who can set the account-s NameID can inject an XML comment that truncates the value used by authentik to the text before the comment while the signed assertion remains valid. A crafted NameID can therefore truncate to a victim-s username or email and bind the attacker-s external identity to the victim-s existing account. This grants full takeover without the victim-s password or the identity provider-s private key, and the malicious link persists so later logins succeed without the comment. Sources using the default unique-identifier matching mode and authentik-s outbound SAML Provider role are not affected. This issue is fixed in versions 2026.2.6 and 2026.5.5.
- Published
- 2026-08-18 17:16:59
- Affected versions
- <2026.2.6, <2026.5.5
- Type
- Web application
- Last modified
- 2026-08-18 18:18:38
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X