---
id: CVE-2026-45052
title: Open Access Management (OpenAM) is an access management solution
summary: >-
  Open Access Management (OpenAM) is an access management solution. Prior to
  16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote
  requests to write persistent entries through SOAPReceiver and DiscoveryService
  into …
severity: critical
cvss: 9.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:L/SA:N'
cwe:
  - CWE-285
vendor: OpenIdentityPlatform
product: OpenAM
affected:
  - OpenAM < 16.1.1
patched:
  - 'org.openidentityplatform.openam:openam-federation-library 16.1.1'
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:17:16.343'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45052'
references:
  - url: >-
      https://github.com/OpenIdentityPlatform/OpenAM/commit/07e402c3f6321fbe5ffdb213f3817f09a8fc81de
    label: security-advisories@github.com
  - url: 'https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-p462-xxwx-pqf4
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-p462-xxwx-pqf4'
tags:
  - nvd
  - cve.org
  - ghsa
  - maven
epss: 0.0046
epssPercentile: 0.39196
ecosystem: maven
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-16T18:05:06.008057Z'
cvssSource: cna
ingestedAt: '2026-06-26T16:43:14.559Z'
---

## Overview

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass requester LDAP and identity ACLs, and the global path uses an internal administrative token. Deployments that consume Liberty discovery data can subsequently use manipulated service-routing or security-mechanism records. This issue is fixed in version 16.1.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-45052)

Affected packages:

- `org.openidentityplatform.openam:openam-federation-library <= 16.0.6`

Patched in:

- `org.openidentityplatform.openam:openam-federation-library 16.1.1`

Source: https://github.com/advisories/GHSA-p462-xxwx-pqf4
