Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 CWE-287 |
Tue, 11 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws. | |
| Title | Picketlink-federation: auth bypass in picketlink saml unsolicited-response | |
| First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform |
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 |
|
| Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T08:49:35.062Z
Reserved: 2026-06-01T17:34:28.463Z
Link: CVE-2026-10579
No data.
Status : Received
Published: 2026-08-11T09:17:12.260
Modified: 2026-08-11T09:17:12.260
Link: CVE-2026-10579
OpenCVE Enrichment
Updated: 2026-08-11T13:45:04Z