A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 CWE-287 |
Tue, 11 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws. | |
| Title | Picketlink-federation: auth bypass in picketlink saml unsolicited-response | |
| First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform |
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 |
|
| Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T08:49:35.062Z
Reserved: 2026-06-01T17:34:28.463Z
Link: CVE-2026-10579
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-11T10:30:04Z