---
id: CVE-2026-105120
title: >-
  OpenAM before 16.1.3 contains an authorization bypass vulnerability in the
  sessions REST endpoint query operation that allows realm administrators to
  list sessions of every realm
summary: >-
  OpenAM before 16.1.3 contains an authorization bypass vulnerability in the
  sessions REST endpoint query operation that allows realm administrators to
  list sessions of every realm. Attackers holding delegated RealmAdmin
  privileges can sup…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: OpenIdentityPlatform
product: OpenAM
affected:
  - OpenAM < 16.1.3
  - OpenAM < 16.1.3
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T14:16:38.853'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105120'
references:
  - url: >-
      https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-x8cj-3hqv-cgwh
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openam-before-16.1.3-cross-realm-session-disclosure-via-sessions-rest-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T14:47:06.465Z'
---

## Overview

OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
