Red HatCVE-2026-15556
Red Hat Picketlink: improper signature check
High8.1CVE-2026-15556 · Published Aug 11, 2026 · updated Sep 25, 2026
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-347
- www.cve.org/CVERecord?id=CVE-2026-15556
- nvd.nist.gov/vuln/detail/CVE-2026-15556
- access.redhat.com/errata/RHSA-2026:53644
- access.redhat.com/errata/RHSA-2026:53645
- access.redhat.com/errata/RHSA-2026:53646
- access.redhat.com/errata/RHSA-2026:53806
- access.redhat.com/security/cve/CVE-2026-15556
- bugzilla.redhat.com/show_bug.cgi?id=2483121
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Red Hat FreeIPA: improper authorization | High8.2 | No fix yet |
| Aug 11 | Red Hat search-v2-api. The authentication middleware: authentication bypass | High7.5 | No fix yet |
| Aug 11 | Red Hat acm-search-v2-api-rhel9.: information disclosure | Medium5.3 | No fix yet |
| Aug 11 | Red Hat insights-client.: information disclosure | High7.1 | No fix yet |
| Aug 11 | Red Hat insights-client. A compromised managed cluster: information disclosure | Medium6.8 | No fix yet |
| Aug 11 | Red Hat insights-client: secrets in logs | Medium6.3 | No fix yet |