HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-15556 — A flaw was found in Picketlink's SP signature validation; a SAML response contai...
·Source: NIST NVD
Updated:
Executive Summary
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
Analysis
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application. CVSS Score: 8.1. Published: 2026-08-11T09:17:12.687.