What is CVE-2026-15556?
CVE-2026-15556 is a flaw in Picketlink's SP signature validation where a SAML response with zero assertion elements is accepted. This allows an attacker to forge a SAML response and authenticate as any principal with any roles on the protected application. Immediate update of the Picketlink library is strongly advised.
Azərbaycanca: CVE-2026-15556 Picketlink-də SP imza doğrulamasında sıfır assertion elementi ilə SAML cavabını qəbul edən bir qüsurdur. Bu, hücumçuya saxta SAML cavabı yaradaraq qorunan tətbiqdə istənilən istifadəçi kimi autentifikasiya olmağa imkan verir. Dərhal Picketlink kitabxanasını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Picketlink
FAQ1
What authentication bypass does CVE-2026-15556 cause in Picketlink?
CVE-2026-15556 allows an attacker to forge a SAML response and authenticate as any principal with any roles on the protected application because Picketlink's SP signature validation accepts a SAML response with zero assertion elements.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.