CVE-2026-68759
A holder of a valid integration credential may impersonate other users under specific conditions.
CVSS
7.2
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 12 ago 2026 · Última mod.: 12 ago 2026 · CWE-347
Sin historial EPSS suficiente todavía.
A holder of a valid integration credential may impersonate other users under specific conditions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-687577.5 ALT—
———A user with access to a valid SAML response may impersonate another user under specific conditions.7hCVE-2026-627575.3 MED—
——0Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.7hCVE-2026-155568.1 ALT8.3%
——2A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.6hCVE-2026-105799.8 CRÍ32.3%
——10A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.1dCVE-2026-667765.9 MED3.6%
——1SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.1dCVE-2026-10754—44.3%
——13Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.1d