CVE-2026-15556
Received Received - Intake

SAML Response Forgery in Picketlink SP Signature Validation

Vulnerability report for CVE-2026-15556, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Red Hat, Inc.

Description

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat picketlink From 8.0 (exc)
redhat picketlink to 8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in PicketLink's SAML 2.0 authentication system. It allows attackers to bypass authentication by forging SAML responses when a response contains zero assertion elements matching the signature check. This happens due to improper handling of XML Signature Wrapping, where a signed assertion is moved outside the validated subtree. The attacker can then authenticate as any user with any roles on the protected application.

Detection Guidance

To detect this vulnerability, inspect SAML responses for zero assertion elements matching signature checks. Monitor logs for unexpected authentication bypasses or unauthorized role assignments. Use SAML validation tools to verify signature checks and assertion counts in responses.

Impact Analysis

If you use PicketLink for SAML-based single sign-on (SSO), an attacker could exploit this to gain unauthorized access to your protected applications. They could impersonate any user and assign arbitrary roles, potentially leading to data breaches, unauthorized actions, or full system compromise. The impact is high due to the ability to bypass authentication entirely.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using PicketLink for SSO may fail compliance audits if they cannot demonstrate adequate protection against authentication bypasses. The risk of data exposure or unauthorized modifications could result in regulatory penalties.

Mitigation Strategies

Immediately upgrade to a patched version of PicketLink or disable SAML-based SSO if not required. Apply vendor-supplied mitigations or patches. For Red Hat JBoss EAP 8.x, no action is needed as it is not affected. Monitor security advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15556. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart