Beveiligingsadvies

CVE-2026-10579

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-11 08:49:35
Laatst bijgewerkt 2026-09-01 11:48:17
Toegewezen door redhat
CVSS-score 9.8
Status PUBLISHED

Beschrijving

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.