{"id":146763,"date":"2026-08-21T00:14:13","date_gmt":"2026-08-21T00:14:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/146763\/"},"modified":"2026-08-21T00:14:13","modified_gmt":"2026-08-21T00:14:13","slug":"claude-ai-finds-full-authentication-bypasses-across-multiple-saml-libraries","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/146763\/","title":{"rendered":"Claude AI Finds Full Authentication Bypasses Across Multiple SAML Libraries"},"content":{"rendered":"<p>\t\t\t    <a href=\"https:\/\/cyberpress.org\/wp-content\/uploads\/2026\/08\/claude-ai-finds-full-authentication-bypasses-across-multiple-saml-libraries-6a86c4fd6ed49.webp\" data-caption=\"\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" post-id=\"82613\" fifulocal-featured=\"1\" width=\"696\" height=\"392\" class=\"entry-thumb td-modal-image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/claude-ai-finds-full-authentication-bypasses-across-multiple-saml-libraries-6a86c4fd6ed49-696x392.we.webp\"   alt=\"Claude AI Finds Full Authentication Bypasses Across Multiple SAML Libraries\" title=\"Claude AI Finds Full Authentication Bypasses Across Multiple SAML Libraries\"\/><\/a>\t\t\t    \t\t\t    <\/p>\n<p class=\"wp-block-paragraph\">A newly disclosed critical vulnerabilities across several open-source SAML implementations through an AI-assisted research pipeline using Anthropic\u2019s Claude Opus. <\/p>\n<p class=\"wp-block-paragraph\">Documented by Eric Chiang, the investigation uncovered full authentication bypasses, weaknesses in XML signature validation, information disclosure risks, arbitrary logout flaws, and <a href=\"https:\/\/cyberpress.org\/anydesk-zero-day-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">denial-of-service conditions<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">SAML remains particularly difficult to implement securely because it depends on XML Digital Signatures. Security issues can emerge when a signature-validation library and the relying application parse or canonicalize the same XML document differently.<\/p>\n<p>Claude AI Finds Full Authentication Bypasses <\/p>\n<p class=\"wp-block-paragraph\"> In those cases, an application may mistakenly accept attacker-controlled content as if it had been cryptographically verified. Chiang developed a multi-agent environment after joining <a href=\"https:\/\/cyberpress.org\/claude-opus-5-finds-software-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Anthropic\u2019s Cyber Verification Program<\/a>. <\/p>\n<p class=\"wp-block-paragraph\">Rather than asking Claude to find specific known flaws, he provided a threat model and allowed the system to investigate unusual behavior in XML processing, parsing, and signature validation within target codebases. <\/p>\n<p class=\"wp-block-paragraph\">The process initially searched for potentially exploitable \u201cgadgets,\u201d such as dangerous canonicalization or transformation behavior, and then attempted to chain confirmed findings into proof-of-concept exploits. <\/p>\n<p class=\"wp-block-paragraph\">Intermediate results were maintained in JSONL records to prioritize leads, remove duplicates, and filter out irrelevant issues before expensive exploit testing.<\/p>\n<p class=\"wp-block-paragraph\">One notable finding affected the Node.js xml-crypto ecosystem. The research identified differences involving the handling of XML processing instructions during canonicalization. <\/p>\n<p class=\"wp-block-paragraph\">This contributed to an email-truncation scenario in OneUptime, where specially crafted XML could cause downstream logic to interpret a signed SAML NameID differently from the signature-validation component.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/oblique.security\/blog\/hacking-saml\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Chiang reported<\/a> complete authentication bypasses in Authentik, litesaml\/lightsaml, OneUptime, and Java saml-client. In Authentik, comment injection within a SAML NameID could truncate an identity value and enable account impersonation; the issue is tracked as CVE-2026-57580. <\/p>\n<p class=\"wp-block-paragraph\">The litesaml\/lightsaml issue, tracked as CVE-2026-63182, involved a SAML Response signature-wrapping flaw. OneUptime and Java saml-client were also affected by SAML Response signature-wrapping weaknesses.<\/p>\n<p class=\"wp-block-paragraph\">Signature wrapping attacks exploit a dangerous mismatch between the XML element validated by a cryptographic library and the element later processed by application code. <\/p>\n<p class=\"wp-block-paragraph\">An attacker can retain a valid signature over a legitimate assertion while directing the application toward a separate malicious assertion. In an affected identity flow, that condition can produce a \u201clogin as anyone\u201d authentication bypass.<\/p>\n<p class=\"wp-block-paragraph\">The Authentik finding drew additional attention because eight independent researchers reportedly disclosed the same flaw simultaneously.<\/p>\n<p class=\"wp-block-paragraph\">The overlap illustrates how AI-assisted tooling may significantly accelerate discovery of well-hidden but repeatable implementation weaknesses.<\/p>\n<p class=\"wp-block-paragraph\">The investigation also <a href=\"https:\/\/cyberpress.org\/anthropic-buffa-library-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">found denial-of-service exposure<\/a> in XML signature processing. Go\u2019s xmldsig library received a fix for a quadratic memory-allocation issue during signature verification. <\/p>\n<p class=\"wp-block-paragraph\">JavaScript\u2019s xmldom reportedly faces similar memory-allocation concerns that can affect Node-based SAML applications. Python SAML packages were also found to permit risky XML signature transformations via libxmlsec1, including XSLT transformations that can expand unauthenticated XML into extremely large documents.<\/p>\n<p class=\"wp-block-paragraph\">The findings underscore why organizations should avoid building custom SAML implementations and instead rely on actively maintained identity software. <\/p>\n<p class=\"wp-block-paragraph\">Teams that must support SAML should enforce strict element selection, use hardened signature-validation APIs, restrict allowed XML transforms, apply parser resource limits, and test for signature-wrapping and canonicalization inconsistencies.<\/p>\n<p class=\"wp-block-paragraph\">Chiang\u2019s research demonstrates that AI can help researchers systematically examine complex protocol assumptions at a scale that conventional manual auditing may struggle to match. <\/p>\n<p class=\"wp-block-paragraph\">However, it also signals a growing challenge for open-source maintainers, who may soon face substantially higher volumes of vulnerability reports generated or accelerated by AI-driven security research.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\">Give your security team the visibility and context to investigate suspicious activity faster and\u00a0contain\u00a0threats before business impact grows.\u00a0<a href=\"https:\/\/any.run\/enterprise\/?utm_source=cyber_press&amp;utm_medium=article&amp;utm_campaign=lazarus&amp;utm_content=enterprise&amp;utm_term=180826#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Strengthen Your Investigations with ANY.RUN<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"A newly disclosed critical vulnerabilities across several open-source SAML implementations through an AI-assisted research pipeline using Anthropic\u2019s Claude&hellip;\n","protected":false},"author":2,"featured_media":146764,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[53,3154,182,1393,9644],"class_list":["post-146763","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-anthropic","tag-anthropic-claude","tag-claude","tag-cyber-security","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/146763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=146763"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/146763\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/146764"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=146763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=146763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=146763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}