What is CVE-2026-10579?
A flaw was found in Picketlink Federation SAML where the unsolicited response handler accepts forged assertions without verification. This allows an unauthenticated attacker to impersonate any principal or role, potentially leading to information disclosure and access to restricted operations. Applying the vendor-supplied security update is strongly recommended.
Azərbaycanca: Picketlink Federation SAML-də aşkar edilmiş bu boşluq, icazəsiz 'unsolicited response' emalı zamanı saxta təsdiqləmələrin (assertions) heç bir yoxlama olmadan qəbul edilməsinə səbəb olur. Bu, autentifikasiya olunmamış hücumçuya istənilən istifadəçi və ya rol adından sistemə daxil olmağa, məxfi məlumatlara çıxış əldə etməyə və məhdud əməliyyatları icra etməyə imkan verir. Dərhal təchizatçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Picketlink
FAQ1
What is the impact of the CVE-2026-10579 vulnerability in Picketlink Federation SAML?
This flaw allows an unauthenticated attacker to submit forged assertions without verification by exploiting the unsolicited response handler. This can lead to impersonation of any principal or role, potentially resulting in information disclosure and access to restricted operations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.