Fedora Account System
Red Hat Associate
Red Hat Customer
Authentication Bypass — PicketLink SP accepts forged SAML 1.1 unsolicited response (no signature check) (JBoss EAP) Complete authentication bypass on any PicketLink-federation SAML SP: the SAML 1.1 unsolicited-response handler accepts forged assertions with no signature verification, no issuer validation, and no audience restriction check, allowing an unauthenticated attacker to authenticate as any principal with any roles using a single crafted POST. findings/jboss-eap_29.md
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 Via RHSA-2026:53644 https://access.redhat.com/errata/RHSA-2026:53644
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4.25 Via RHSA-2026:53806 https://access.redhat.com/errata/RHSA-2026:53806