CRITICAL 9.8 NVD
CVE-2026-10579
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
References
- https://access.redhat.com/security/cve/CVE-2026-10579
- https://bugzilla.redhat.com/show_bug.cgi?id=2480325
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-11 via NVD.
Risk Timeline
CVE Disclosed2026-08-11 · -1 days ago
Remediation Resources
Official Advisory
access.redhat.com/security/cve/CVE-2026-10579Analysis & PoC
bugzilla.redhat.com/show_bug.cgi?id=2480325
vulnfeed aggregates 9850 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.