Researchers reported a new wave of SAML authentication bypass flaws affecting multiple libraries and products, including Authentik, PHP litesaml/lightsaml, OneUptime, java-saml-client, and earlier-disclosed Ruby and PHP SAML ecosystems. The findings describe parser-level inconsistencies, XML signature wrapping, namespace confusion, attribute pollution, and a "Void Canonicalization" technique that can desynchronize XML signature verification from assertion parsing, allowing attackers to present a well-formed SAML document that still bypasses validation. In the most prominent case, CVE-2026-57580 in Authentik allowed abuse of XML comments in a NameID value under certain non-default account-matching modes, potentially linking an attacker-controlled identity to a victim account and enabling account takeover.
The disclosures show both practical exploitation and vendor response. PortSwigger demonstrated real-world impact against GitLab EE 17.8.4 and said fixes were issued for xmlseclibs 3.1.4 and Ruby-SAML advisories tied to CVE-2025-66567 and CVE-2025-66568. Separate reporting said JFrog directly credited Ben Morris working with Claude and Anthropic Research across four authentication-related flaws, including a SAML signature-verification issue, while Authentik patched its bug in versions 2026.2.6 and 2026.5.5. The broader research also identified signature-validation bypasses in authentication requests, attribute queries, and logout flows, along with denial-of-service risks from malicious XML inputs.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Cyber Security News reported on Oblique Security's Claude-assisted research into SAML implementations, highlighting authentication bypasses, account-takeover risk, and denial-of-service findings. The article emphasized CVE-2026-57580 in Authentik and the broader risks from parser differentials and signature wrapping.
Oblique Security published findings describing full authentication bypasses in four projects: Authentik, PHP litesaml/lightsaml, OneUptime, and Java saml-client. The report said three cases involved SAML signature wrapping and also documented signature-validation bypasses in authentication requests, attribute queries, and logout operations.
Bugflation summarized four JFrog CNA CVE records that directly credited Ben Morris in collaboration with Claude and Anthropic Research. The referenced issues covered a post-user-deletion credential window, writable-session-data deserialization, SAML signature-verification behavior, and a remember-me cache authentication bypass.
Zakhar Fedotkin published research describing new SAML authentication bypass classes in Ruby and PHP implementations, including attribute pollution, namespace confusion, and 'Void Canonicalization.' The work included practical exploitation claims and a demo against GitLab EE 17.8.4.
Authentik fixed CVE-2026-57580, a flaw involving XML comments in a SAML NameID value that could enable account linking and takeover under certain non-default matching modes. The fixes were released in versions 2026.2.6 and 2026.5.5.
A researcher at Oblique Security built an AI-assisted testing harness around Anthropic's Claude Opus to examine how SAML libraries and applications handled signed XML. The investigation identified serious flaws that could enable authentication bypass, account takeover, and denial of service.
The PortSwigger research states that xmlseclibs version 3.1.4 was released to fix a libxml2 canonicalization vulnerability tied to the 'Void Canonicalization' attack class. The issue affected PHP XMLDSig implementations relying on vulnerable behavior.
According to the research, Ruby-SAML maintainers announced CVE-2025-66568 and CVE-2025-66567 affecting all versions before 1.18.0, including 1.12.4. The advisories addressed the newly described SAML bypass issues.
Ruby-SAML released versions 1.12.4 and 1.18.0 to mitigate earlier DTD-handling issues. The research says 1.12.4 rejected DTDs and required well-formed XML but did not fix the underlying multi-parser design problem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceoblique.security
Open sourcebugflation.com
Open sourceprovos.org
Open sourceportswigger.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.