{"id":145884,"date":"2026-08-20T08:51:06","date_gmt":"2026-08-20T08:51:06","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/145884\/"},"modified":"2026-08-20T08:51:06","modified_gmt":"2026-08-20T08:51:06","slug":"claude-ai-finds-saml-security-flaws-that-can-let-attackers-take-over-accounts","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/145884\/","title":{"rendered":"Claude AI Finds SAML Security Flaws That Can Let Attackers Take Over Accounts"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Security researchers have used Anthropic\u2019s Claude AI to uncover serious <a href=\"https:\/\/cybersecuritynews.com\/saml-bypass-authentication-on-github-enterprise-servers\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">flaws in Security Assertion Markup Language (SAML) <\/a>implementations that could allow attackers to bypass authentication and take over user accounts.<\/p>\n<p class=\"wp-block-paragraph\">The findings highlight the persistent security risks created by XML signature processing, inconsistent parser behavior, and custom SAML code.<\/p>\n<p class=\"wp-block-paragraph\">A researcher at Oblique Security built an AI-assisted testing harness around<a href=\"https:\/\/cybersecuritynews.com\/claude-opus-5-finds-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> Claude Opus to examine<\/a> SAML libraries and applications.<\/p>\n<p class=\"wp-block-paragraph\">Rather than directing the model to reproduce known bugs, the system supplied a threat model and let Claude explore how each implementation handled signed XML data.<\/p>\n<p class=\"wp-block-paragraph\">The process separated the discovery of unusual parser behavior from validation, in which the model attempted to create a working end-to-end exploit.<\/p>\n<p>Claude AI Finds SAML Flaws <\/p>\n<p class=\"wp-block-paragraph\">SAML is widely used for enterprise <a href=\"https:\/\/cybersecuritynews.com\/single-sign-on-solutions\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">single sign-on<\/a>, allowing an identity provider to send signed authentication assertions to a service provider. However, secure implementation depends on both components interpreting the same XML document in the same way.<\/p>\n<p class=\"wp-block-paragraph\">When signature verification and application logic process XML differently, attackers may be able to supply unsigned identity data that the application mistakenly trusts.<\/p>\n<p class=\"wp-block-paragraph\">The research identified full authentication bypasses in four projects, including Authentik, PHP litesaml\/lightsaml, OneUptime, and Java saml-client.<\/p>\n<p class=\"wp-block-paragraph\">In three cases, the issue involved<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-abuse-proofpoints-link-wrapping-features\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> SAML signature wrapping<\/a>, a long-standing attack class in which an attacker moves or injects XML elements so that a valid signature is verified on a different object. At the same time, the application reads identity information from another.<\/p>\n<p class=\"wp-block-paragraph\">The most notable issue affected Authentik, an open-source identity provider. Tracked as CVE-2026-57580, the flaw allowed an attacker to use an XML comment inside a SAML NameID value.<\/p>\n<p class=\"wp-block-paragraph\">Under certain non-default account-matching modes, Authentik could interpret the value before the comment as a victim\u2019s username or email, even while the signed assertion remained valid. This could link an attacker-controlled external identity to the victim\u2019s account, creating a persistent path to account takeover.<\/p>\n<p class=\"wp-block-paragraph\">Authentik fixed the vulnerability in versions 2026.2.6 and 2026.5.5. Organizations using inbound SAML sources with USERNAME_LINK or EMAIL_LINK matching should verify that they have applied the update.<\/p>\n<p class=\"wp-block-paragraph\">The vendor noted that default unique-identifier matching and outbound SAML provider deployments were not affected. The investigation also uncovered weaknesses outside standard SAML login responses.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/oblique.security\/blog\/hacking-saml\/\" data-type=\"link\" data-id=\"https:\/\/oblique.security\/blog\/hacking-saml\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to Oblique Security research<\/a>, signature validation bypasses in authentication requests, attribute queries, and logout operations could enable information disclosure or arbitrary user logouts.<\/p>\n<p class=\"wp-block-paragraph\">Denial-of-service risks were also common. Several libraries accepted attacker-controlled XML documents that could trigger excessive memory usage during signature validation or XML transformation.<\/p>\n<p class=\"wp-block-paragraph\">Such weaknesses are especially dangerous because they can often be exploited before authentication. The findings reinforce a familiar message for identity teams: avoid custom SAML implementations whenever possible.<\/p>\n<p class=\"wp-block-paragraph\">Developers should use mature, actively maintained libraries, strictly validate signed elements, turn off dangerous XML transforms, impose document-size and resource limits, and test identity flows for parser differentials and signature wrapping attacks.<\/p>\n<p class=\"wp-block-paragraph\">AI can accelerate vulnerability discovery, but it can also expose how fragile legacy XML-based authentication implementations remain.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\">Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:\u00a0<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=csn&amp;utm_medium=100+links&amp;utm_campaign=lookup+tier+1&amp;utm_content=ti+lookup+sales&amp;utm_term=190826#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Integrate TI\u00a0Lookup in\u00a0your SOC<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Security researchers have used Anthropic\u2019s Claude AI to uncover serious flaws in Security Assertion Markup Language (SAML) implementations&hellip;\n","protected":false},"author":2,"featured_media":145885,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[53,3154,182],"class_list":["post-145884","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-anthropic","tag-anthropic-claude","tag-claude"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/145884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=145884"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/145884\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/145885"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=145884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=145884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=145884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}