CVE-2026-45049High· 8.3▾ TwilightOpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Description
An Information Exposure Through Sent Data (CWE-201) issue in OpenAM's Cross-Domain Single Sign-On (CDSSO) servlet allows a logged-in user's raw OpenAM session token to be POSTed to an attacker-controlled URL. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1.
An attacker who can induce a logged-in victim to visit a crafted URL may receive the victim's session credential, which could enable session hijacking.
OpenAM deployments through version 16.0.6 that have CDSSO enabled are potentially affected. The CDSSO component is commonly enabled in multi-domain deployments. Exploitation requires user interaction — an authenticated user must be induced to visit an attacker-crafted URL — and is further gated on a non-default configuration being absent.
This has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.
org.openidentityplatform.openam:openam-federation <= 16.0.6Upgrade to a patched release:
org.openidentityplatform.openam:openam-federation 16.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53660High· 7.4Open Access Management (OpenAM) is an access management solution
GHSA-68r5-9hpg-7qw9Critical· 9.4OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-p279-2cqp-84jgCritical· 9.6OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
CVE-2026-62263Critical· 9.2Open Access Management (OpenAM) is an access management solution
CVE-2026-62280Medium· 6.1Open Access Management (OpenAM) is an access management solution
CVE-2026-62379Critical· 9.8Open Access Management (OpenAM) is an access management solution