---
id: CVE-2026-105121
title: >-
  OpenAM before 16.1.3 contains an improper authorization vulnerability that
  allows delegated administrators to destroy sessions outside their realms
  because realm checks use the requester's realm
summary: >-
  OpenAM before 16.1.3 contains an improper authorization vulnerability that
  allows delegated administrators to destroy sessions outside their realms
  because realm checks use the requester's realm. Authenticated accounts holding
  the iplane…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-285
vendor: OpenIdentityPlatform
product: OpenAM
affected:
  - OpenAM < 16.1.3
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T14:16:38.997'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105121'
references:
  - url: >-
      https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T14:47:06.466Z'
---

## Overview

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
