CVE-2026-10579
🟠 Łataj w tym tygodniu
Błąd w Picketlink Federation SAML pozwala atakującemu na fałszowanie uwierzytelnień.
CVSS
9.8
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-08-11 09:17:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-18 00:16:53 UTC |
Referencje
- https://access.redhat.com/errata/RHSA-2026:53644 ([email protected])
- https://access.redhat.com/errata/RHSA-2026:53645 ([email protected])
- https://access.redhat.com/errata/RHSA-2026:53646 ([email protected])
- https://access.redhat.com/errata/RHSA-2026:53806 ([email protected])
- https://access.redhat.com/security/cve/CVE-2026-10579 ([email protected])
- https://bugzilla.redhat.com/show_bug.cgi?id=2480325 ([email protected])