AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15556

HIGH · CVSS 8.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in Picketlink's SP signature validation allows attackers to forge SAML responses by exploiting a flaw that permits zero assertion elements to pass the signature check. This could enable unauthorized authentication as any user with any roles within the targeted application. Organizations utilizing Picketlink for SAML authentication should prioritize addressing this issue to prevent potential identity and access management breaches.

CVE
CVE-2026-15556
Severity
HIGH
CVSS
8.1
EPSS
0.22%

Original NVD Description

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.