CVE-2026-10579
Received Received - Intake

SAML Authentication Bypass in Picketlink Federation

Vulnerability report for CVE-2026-10579, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Red Hat, Inc.

Description

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat picketlink_federation *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-10579 is a flaw in PicketLink Federation SAML where the unsolicited response handler fails to verify or validate SAML assertions. This allows an unauthenticated attacker to forge assertions and authenticate as any user or role without proper checks like signature verification or issuer validation.

Detection Guidance

To detect this vulnerability, check if your system uses PicketLink Federation SAML SP and if it processes unsolicited SAML responses. Inspect SAML responses for missing signature verification, issuer validation, or audience restriction. Use network monitoring tools to detect POST requests containing SAML assertions without prior authentication requests.

Impact Analysis

This vulnerability could lead to unauthorized access to systems, information disclosure, or execution of restricted operations. An attacker could impersonate any user, bypass authentication controls, and gain elevated privileges, potentially compromising the entire system.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by enabling unauthorized access to sensitive data, leading to data breaches. Organizations using PicketLink Federation SAML may face regulatory penalties due to inadequate authentication controls.

Mitigation Strategies

Immediately upgrade to a patched version of PicketLink Federation. If no patch is available, disable unsolicited SAML responses or configure the SP to enforce strict validation of assertions. Consult Red Hat documentation for specific mitigation steps for JBoss EAP or related products.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10579. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart