Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-10579: Picketlink Federation SAML: Auth Bypass via Fake Authentication
CVE-2026-10579 · published 1 month ago
Summary
Picketlink Federation SAML is affected, allowing an unauthorized attacker to impersonate users and access sensitive information or restricted functions. This could lead to unauthorized access to sensitive data or operations. To mitigate this, ensure proper configuration and validation of SAML responses.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | red hat jboss enterprise application platform 7 | All versions |
| red hat | red hat jboss enterprise application platform 8 | All versions |
| red hat | red hat jboss enterprise application platform 7.4.25 | All versions |
| red hat | red hat jboss enterprise application platform 7.4 els on rhel 7 | All versions |
| red hat | red hat jboss enterprise application platform 7.4 els on rhel 8 | All versions |
| red hat | red hat jboss enterprise application platform 7.4 els on rhel 9 | All versions |
Original advisory text
Picketlink-federation: auth bypass in picketlink saml unsolicited-response
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
References
- https://access.redhat.com/security/cve/CVE-2026-10579
- https://bugzilla.redhat.com/show_bug.cgi?id=2480325
- https://access.redhat.com/errata/RHSA-2026:53644
- https://access.redhat.com/errata/RHSA-2026:53645
- https://access.redhat.com/errata/RHSA-2026:53646
- https://access.redhat.com/errata/RHSA-2026:53806
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published11 Aug 2026
Updated1 Oct 2026
First seen11 Aug 2026
Track software like this
Free during beta