A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 09:17
Updated : 2026-09-01 12:17
NVD link : CVE-2026-10579
Mitre link : CVE-2026-10579
CVE.ORG link : CVE-2026-10579
JSON object : View
Products Affected
No product.
CWE
CWE-347
Improper Verification of Cryptographic Signature
