CRITICAL 9.8 NVD

CVE-2026-10579

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

References

Published: 2026-08-11 · Source: NVD · Feed updated: 2026-08-11
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-11 via NVD.

Risk Timeline

CVE Disclosed2026-08-11 · -1 days ago

Remediation Resources

vulnfeed aggregates 9850 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.