A vulnerability classified as critical was found in PicketLink. The impacted element is an unknown function of the component Federation. Such manipulation leads to authorization bypass.

This vulnerability is referenced as CVE-2026-15556. It is possible to launch the attack remotely. No exploit is available.