Beveiligingsadvies

CVE-2026-15556

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-11 08:49:44
Laatst bijgewerkt 2026-08-24 11:38:27
Toegewezen door redhat
CVSS-score 8.1
Status PUBLISHED

Beschrijving

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.