Skip to content
Threat Feed
critical advisory

PicketLink Federation SAML Authentication Bypass via Forged Assertions

A vulnerability in the PicketLink Federation SAML unsolicited response handler allows unauthenticated attackers to forge assertions, resulting in full authentication bypass as any principal.

CVE search metadata

CVE search record: CVE-2026-10579. Severity: critical. CVSS: 9.8. EPSS: n/a. KEV: no. Product: PicketLink Federation. Brief: PicketLink Federation SAML Authentication Bypass via Forged Assertions. Brief link: https://feed.craftedsignal.io/briefs/2026-08-picketlink-saml-auth-bypass/

CVE-2026-10579 describes a critical authentication bypass vulnerability identified in the PicketLink Federation SAML component. The vulnerability exists within the unsolicited response handler, which fails to perform necessary cryptographic verification or structural validation of incoming SAML assertions. An attacker can craft a malicious, forged SAML assertion to impersonate any user within the target system, including users with administrative roles. Because the service does not validate the integrity or the origin of the unsolicited SAML response, the application incorrectly trusts the forged identity claims. This flaw exposes affected systems to unauthorized information access, the performance of sensitive operations on behalf of other users, and full account takeover. The impact is significant, warranting immediate investigation into implementations using PicketLink for SAML-based authentication.

Impact

Successful exploitation allows unauthenticated attackers to assume the identity of any principal, including highly privileged administrative accounts. This leads to complete compromise of confidentiality, integrity, and availability within the target application. Potential damage includes unauthorized exfiltration of sensitive organizational data, modification of application state, and execution of restricted administrative functions, effectively negating the organization's authentication perimeter.

Recommendation

  • Identify all instances of PicketLink Federation within the enterprise environment and verify the version in use.
  • Apply security patches provided by Red Hat as soon as they become available.
  • Monitor authentication logs for anomalous SAML assertion patterns, specifically identifying unsolicited responses from unexpected or non-standard Identity Providers.
  • Review application access logs for account changes or administrative actions initiated by accounts that lack corresponding successful login sessions in external IdP logs.

Immediate actions

Patch affected PicketLink Federation instances per Red Hat security advisory.

IT Operations 48h

Threat Hunt

Audit access logs for accounts demonstrating administrative behavior without prior SSO session authentication.

T1550.001 high medium confidence hunt now

Data: Application authentication logs