CVE-2026-57580 is an account-takeover vulnerability in authentik, an open-source identity provider, affecting inbound SAML Source configurations that use the non-default USERNAME_LINK or EMAIL_LINK user-matching modes. In vulnerable versions, authentik interprets an XML comment embedded in a SAML NameID differently from the source identity provider’s signed assertion. An attacker who has an account on the source identity provider and can control that account’s NameID can craft a signed assertion containing a NameID with an XML comment such that authentik truncates the value at the comment boundary for account matching, while the assertion itself remains validly signed. By causing the truncated value to match a victim’s username or email address, the attacker can bind their external identity to the victim’s existing authentik account. The issue affects versions prior to 2026.2.6 and prior to 2026.5.5 in the 2026.5 release line. Sources using the default unique-identifier matching mode and authentik’s outbound SAML Provider role are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass/account takeover vulnerability in Authentik’s SAML handling caused by differential XML parsing of a signed NameID value containing an XML comment, allowing attacker-controlled identity linkage to a victim account under certain non-default matching modes.
An account takeover vulnerability in goauthentik authentik's inbound SAML Source handling, where XML comments in NameID can cause mismatched interpretation and allow an attacker to bind their external identity to a victim's existing account.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.