---
id: CVE-2026-10579
title: >-
  A flaw was found in Picketlink Federation SAML; the unsolcited response
  handler would accept forged assertions with no verification or validation,
  permitting an unauthed attacker to authenticate as any principal in any role
summary: >-
  A flaw was found in Picketlink Federation SAML; the unsolcited response
  handler would accept forged assertions with no verification or validation,
  permitting an unauthed attacker to authenticate as any principal in any role.
  This could l…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-347
vendor: Red Hat
product: org.picketlink/picketlink-federation
affected:
  - org.picketlink/picketlink-federation (all versions)
  - eap7-activemq-artemis (all versions)
  - eap7-glassfish-jsf (all versions)
  - eap7-ironjacamar (all versions)
  - eap7-jackson-annotations (all versions)
  - eap7-jackson-core (all versions)
  - eap7-jackson-databind (all versions)
  - eap7-jackson-jaxrs-providers (all versions)
  - eap7-jackson-modules-base (all versions)
  - eap7-jackson-modules-java8 (all versions)
  - eap7-jboss-remoting (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-netty (all versions)
  - eap7-netty-transport-native-epoll (all versions)
  - eap7-picketlink-bindings (all versions)
  - eap7-picketlink-federation (all versions)
  - eap7-undertow (all versions)
  - eap7-wildfly (all versions)
  - eap7-activemq-artemis (all versions)
  - eap7-glassfish-jsf (all versions)
  - eap7-ironjacamar (all versions)
  - eap7-jackson-annotations (all versions)
  - eap7-jackson-core (all versions)
  - eap7-jackson-databind (all versions)
  - eap7-jackson-jaxrs-providers (all versions)
  - eap7-jackson-modules-base (all versions)
  - eap7-jackson-modules-java8 (all versions)
  - eap7-jboss-remoting (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-netty (all versions)
  - eap7-netty-transport-native-epoll (all versions)
  - eap7-picketlink-bindings (all versions)
  - eap7-picketlink-federation (all versions)
  - eap7-undertow (all versions)
  - eap7-wildfly (all versions)
  - eap7-activemq-artemis (all versions)
  - eap7-glassfish-jsf (all versions)
  - eap7-ironjacamar (all versions)
  - eap7-jackson-annotations (all versions)
  - eap7-jackson-core (all versions)
  - eap7-jackson-databind (all versions)
  - eap7-jackson-jaxrs-providers (all versions)
  - eap7-jackson-modules-base (all versions)
  - eap7-jackson-modules-java8 (all versions)
  - eap7-jboss-remoting (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-netty (all versions)
  - eap7-netty-transport-native-epoll (all versions)
  - eap7-picketlink-bindings (all versions)
  - eap7-picketlink-federation (all versions)
patched:
  - jboss_eap_7_4_els_for_rhel_7_server
  - jboss_enterprise_application_platform 7.4.25
published: '2026-08-11'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:17:06.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10579'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:53644'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53645'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53646'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53806'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-10579'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2480325'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10579.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-10579'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10579'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-08-11T16:06:00.151230Z'
epss: 0.00322
epssPercentile: 0.22658
ingestedAt: '2026-09-16T21:05:36.901Z'
---

## Overview

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:53644** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53644)
- **RHSA-2026:53806** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.4.25 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53806)
- **RHSA-2026:53645** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 8 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53645)
- **RHSA-2026:53646** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 9 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53646)
- **Red Hat VEX** · Critical · affected: Red Hat JBoss Enterprise Application Platform 7 · no fix planned: Red Hat JBoss Enterprise Application Platform 7 · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10579.json)
