CVE-2026-15556: Red Hat JBoss Enterprise Application Platform 7
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
Affected products
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4.25: before 2.5.5.SP12-redhat-00016 (fixed in 2.5.5.SP12-redhat-00016)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 7: before 0:2.16.0-22.redhat_00057.1.el7eap (fixed in 0:2.16.0-22.redhat_00057.1.el7eap); before 0:2.3.14-11.SP11_redhat_00001.1.el7eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el7eap); before 0:1.5.26-2.Final_redhat_00001.1.el7eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el7eap); before 0:2.18.8-1.redhat_00003.1.el7eap (fixed in 0:2.18.8-1.redhat_00003.1.el7eap); before 0:5.0.31-3.SP2_redhat_00001.1.el7eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el7eap); before 0:1.10.0-46.Final_redhat_00044.1.el7eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el7eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 8: before 0:2.16.0-22.redhat_00057.1.el8eap (fixed in 0:2.16.0-22.redhat_00057.1.el8eap); before 0:2.3.14-11.SP11_redhat_00001.1.el8eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el8eap); before 0:1.5.26-2.Final_redhat_00001.1.el8eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el8eap); before 0:2.18.8-1.redhat_00003.1.el8eap (fixed in 0:2.18.8-1.redhat_00003.1.el8eap); before 0:5.0.31-3.SP2_redhat_00001.1.el8eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el8eap); before 0:1.10.0-46.Final_redhat_00044.1.el8eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el8eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 9: before 0:2.16.0-22.redhat_00057.1.el9eap (fixed in 0:2.16.0-22.redhat_00057.1.el9eap); before 0:2.3.14-11.SP11_redhat_00001.1.el9eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el9eap); before 0:1.5.26-2.Final_redhat_00001.1.el9eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el9eap); before 0:2.18.8-1.redhat_00003.1.el9eap (fixed in 0:2.18.8-1.redhat_00003.1.el9eap); before 0:5.0.31-3.SP2_redhat_00001.1.el9eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el9eap); before 0:1.10.0-46.Final_redhat_00044.1.el9eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el9eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
Published 2026-08-11. Last modified 2026-09-25.