AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-10579

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the Picketlink Federation SAML implementation, where the unsolicited response handler fails to verify or validate assertions, allowing unauthenticated attackers to impersonate any user. This flaw poses significant risks, including unauthorized access to sensitive information and restricted operations. Organizations utilizing Picketlink should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-10579
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%

Original NVD Description

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.