SAML Response Forgery Vulnerability in Picketlink by Red Hat
CVE-2026-15556
8.1HIGH
What is CVE-2026-15556?
A security flaw exists in the SAML signature validation mechanism of Picketlink. This vulnerability allows an attacker to craft a modified SAML response that could bypass authentication checks, ultimately enabling unauthorized access to applications. If a response contains zero assertion elements matching the signature validation, the system may incorrectly grant access to the attacker, allowing them to assume any user's identity and exploit any roles assigned to that user within the application.