Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-10579: Picketlink Federation SAML: Auth Bypass via Fake Authentication

CVE-2026-10579 · published 1 month ago
Summary

Picketlink Federation SAML is affected, allowing an unauthorized attacker to impersonate users and access sensitive information or restricted functions. This could lead to unauthorized access to sensitive data or operations. To mitigate this, ensure proper configuration and validation of SAML responses.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
red hat red hat jboss enterprise application platform 7 All versions
red hat red hat jboss enterprise application platform 8 All versions
red hat red hat jboss enterprise application platform 7.4.25 All versions
red hat red hat jboss enterprise application platform 7.4 els on rhel 7 All versions
red hat red hat jboss enterprise application platform 7.4 els on rhel 8 All versions
red hat red hat jboss enterprise application platform 7.4 els on rhel 9 All versions
Original advisory text
Picketlink-federation: auth bypass in picketlink saml unsolicited-response
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published11 Aug 2026
Updated1 Oct 2026
First seen11 Aug 2026
Sources
CVE-2026-10579 · MITRE
Track software like this
Free during beta