A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Picketlink's SP (Service Provider) signature validation contains a critical flaw that allows attackers to forge SAML responses by submitting responses with zero assertion elements that match signature checks. This vulnerability enables attackers to bypass authentication entirely and assume the identity of any principal with arbitrary roles on protected applications. Organizations using Picketlink for federated identity and access management—particularly those relying on SAML-based SSO—face immediate risk of unauthorized access to sensitive systems and data. The CVSS score of 8.1 reflects the high severity: successful exploitation requires no user interaction and grants complete authentication bypass with elevated privileges.
While this CVE lacks direct MITRE ATT&CK technique mappings, Casky.ai practitioners can leverage Claude's extended reasoning capabilities to identify the underlying attack patterns: threat actors would need to craft malformed SAML responses (T1566 - Phishing: Spearphishing Link or T1199 - Trusted Relationship exploitation if using federation). Detection focuses on anomalous SAML assertion structures—specifically responses missing expected assertion elements or containing validation mismatches—which would appear in SAML logs, IdP audit trails, and authentication debug output. Practitioners using Casky would see findings correlating unusual SAML response formatting with successful authentication events, indicating potential signature validation bypass attempts. Monitoring for the mismatch between assertion count and signature validation results becomes the key detection signal for this vulnerability class.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-15556. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation