{"id":"CVE-2026-33439","title":"Open Access Management (OpenAM) is an access management solution","summary":"Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"vendor":"openidentityplatform","product":"openam","affected":["openam < 16.0.6"],"patched":["openam 16.0.6"],"published":"2026-04-07","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33439","references":[{"url":"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-2cqq-rpvq-g5qj","label":"security-advisories@github.com"}],"tags":["nvd","exploit-available"],"epss":0.10005,"epssPercentile":0.95396,"ingestedAt":"2026-07-25T23:05:58.053Z","exploits":{"github":6,"githubRepos":["https://github.com/shreyas-malhotra/CVE-2026-33439-OpenAM","https://github.com/Ibonok/CVE-2026-33439-PoC","https://github.com/TheMalwareGuardian/CVE-2026-33439"],"nuclei":["CVE-2026-33439"],"checkedAt":"2026-09-23T07:13:59.292Z"},"exploitAvailable":true,"slug":"CVE-2026-33439","body":"## Overview\n\nOpen Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitigation that was applied to the jato.pageSession parameter after CVE-2021-35464. An unauthenticated attacker can achieve arbitrary command execution on the server by sending a crafted serialized Java object as the jato.clientSession GET/POST parameter to any JATO ViewBean endpoint whose JSP contains <jato:form> tags (e.g., the Password Reset pages). This vulnerability is fixed in 16.0.6.\n\n## Affected\n\n- `openam < 16.0.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openam 16.0.6`","depth":"abyssal","depthScore":68,"depthScoreParts":{"impact":53.9,"likelihood":2,"exploitation":12,"ransomware":0},"changes":[{"seq":5106,"id":"CVE-2026-33439","ts":1788887248566,"field":"exploit_available","old":"false","new":"true"},{"seq":3989,"id":"CVE-2026-33439","ts":1788886364220,"field":"exploit_available","old":"true","new":"false"},{"seq":2804,"id":"CVE-2026-33439","ts":1788883030934,"field":"exploit_available","old":"false","new":"true"},{"seq":1833,"id":"CVE-2026-33439","ts":1788882433848,"field":"exploit_available","old":"true","new":"false"},{"seq":931,"id":"CVE-2026-33439","ts":1788881867576,"field":"exploit_available","old":"false","new":"true"}]}