SAML Response Forgery Vulnerability in Picketlink by Red Hat
CVE-2026-15556

8.1HIGH

What is CVE-2026-15556?

A security flaw exists in the SAML signature validation mechanism of Picketlink. This vulnerability allows an attacker to craft a modified SAML response that could bypass authentication checks, ultimately enabling unauthorized access to applications. If a response contains zero assertion elements matching the signature validation, the system may incorrectly grant access to the attacker, allowing them to assume any user's identity and exploit any roles assigned to that user within the application.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.