SAML Response Forgery Vulnerability in Picketlink by Red Hat
CVE-2026-15556
Key Information:
What is CVE-2026-15556?
A security flaw exists in the SAML signature validation mechanism of Picketlink. This vulnerability allows an attacker to craft a modified SAML response that could bypass authentication checks, ultimately enabling unauthorized access to applications. If a response contains zero assertion elements matching the signature validation, the system may incorrectly grant access to the attacker, allowing them to assume any user's identity and exploit any roles assigned to that user within the application.
Affected Version(s)
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.3.14-11.SP11_redhat_00001.1.el7eap
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:1.5.26-2.Final_redhat_00001.1.el7eap