A critical (CVSS 9.8) authentication bypass in PicketLink Federation's SAML unsolicited response handler lets an unauthenticated attacker forge assertions and log in as any principal in any role.
What Is It
Red Hat disclosed a flaw in PicketLink Federation SAML where the unsolicited response handler accepts forged assertions with no verification or validation. Because the handler performs no signature or content validation, an attacker who can reach the service provider endpoint can craft a SAML response asserting any identity and any role membership; no credentials, no user interaction, no prior access required.
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8, CRITICAL. The maximum exploitability subscore (3.9) reflects that this is remotely reachable, low-complexity, and entirely unauthenticated.
Why It Matters
This is a total authentication bypass on the component whose entire job is authentication. Red Hat notes the impact as information disclosure, access to restricted operations, or other flaws; in practice, an attacker chooses the principal and role they want to be, including administrative ones. SAML federation is typically deployed in front of internal applications, so a successful bypass grants access to whatever resources those applications protect.
CVE-2026-10579 does not appear in CISA's Known Exploited Vulnerabilities catalog as of publication; a status readers can confirm directly against the catalog, linked below. Absence from KEV is not evidence that exploitation is not occurring; it means CISA has not published a confirmation, and no confirmation of active exploitation appears in the vendor or NVD records for this CVE.
What's Vulnerable
- Red Hat JBoss Enterprise Application Platform 7: package
picketlink-federation, default status affected (cpe:/a:redhat:jboss_enterprise_application_platform:7) - Red Hat JBoss Enterprise Application Platform 8: package
picketlink-federation, default status unaffected (cpe:/a:redhat:jboss_enterprise_application_platform:8)
Organizations running SAML federation on JBoss EAP 7 should treat any exposed service provider endpoint as reachable by an unauthenticated attacker.
Patch Status
The CVE was published 2026-08-11 with NVD status Received, and no fixed version, mitigation, or required-action deadline is specified in the supplied data. Red Hat distributes affected software through its restricted software listing; consult the Red Hat CVE page and Bugzilla entry below for current errata status.
Sources
- NVD, CVE-2026-10579: https://nvd.nist.gov/vuln/detail/CVE-2026-10579
- Red Hat Security; CVE-2026-10579: https://access.redhat.com/security/cve/CVE-2026-10579
- Red Hat Bugzilla #2480325: https://bugzilla.redhat.com/show_bug.cgi?id=2480325
- Red Hat JBoss software downloads: https://access.redhat.com/jbossnetwork/restricted/listSoftware.html
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog