Bug 2483121 (CVE-2026-15556)

Summary: CVE-2026-15556 picketlink-federation: picketlink SAML 2.0 auth bypass via missing assertions
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anujha, asoldano, bbaranow, bmaxwell, bstansbe, dlofthou, istudens, ivassile, iweiss, mosmerov, msvehla, nwallace, pberan, pesilva, pjindal, pmackay, rstancel, security-response-team, smaestri, thjenkin, vdosoudi
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-28 23:57:02 UTC
initial report doc: https://docs.google.com/document/d/1Rf4NtLudECimDNy8F9clUblm6Avx8_yF/edit

relevant section info:
XML Signature Wrapping — PicketLink SP signedAssertions==0 short-circuit (SAML 2.0 auth bypass) (JBoss EAP)

SAML 2.0 authentication bypass: PicketLink's SP signature-validation logic short-circuits when the SAML Response contains zero Assertion elements matching the signature check (e.g. the signed assertion is moved outside the validated subtree via XML Signature Wrapping), allowing an attacker to forge a SAML Response and authenticate as any principal with any roles on the protected application.
findings/jboss-eap_30.md

Comment 1 errata-xmlrpc 2026-08-11 16:37:37 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7

Via RHSA-2026:53644 https://access.redhat.com/errata/RHSA-2026:53644

Comment 2 errata-xmlrpc 2026-08-11 17:42:27 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4.25

Via RHSA-2026:53806 https://access.redhat.com/errata/RHSA-2026:53806

Comment 3 Jon Orris 2026-09-17 17:47:31 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9

Via RHSA-2026:53646 https://access.redhat.com/errata/RHSA-2026:53646

Comment 4 Jon Orris 2026-09-17 17:49:15 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8

Via RHSA-2026:53645 https://access.redhat.com/errata/RHSA-2026:53645