VulnSea

OpenIdentityPlatform has 24 CVEs on record. Disclosure cadence is accelerating: 22 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 19. The median CVSS is 8.3 (high), with 10 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-502 (5) and CWE-285 (4). Most affected products: OpenAM (19), OpenDJ (1), org.openidentityplatform.openam:openam-federation (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.3
Publish → KEV
Last 90 days
22 prev 2

Products

  • OpenAM 19
  • OpenDJ 1
  • org.openidentityplatform.openam:openam-federation 1
  • org.openidentityplatform.openam:openam-radius 1
  • org.openidentityplatform.opendj:opendj-dsml-servlet 1
  • org.openidentityplatform.opendj:opendj-server-legacy 1
Follow OpenIdentityPlatform:RSS feedSave a search →Embed badge ↗
24
Total CVEs
10
Critical
0
CISA KEV
0
Exploited

OpenIdentityPlatform vulnerabilities

CVEs affecting OpenIdentityPlatform, newest first. Open any entry for full detail, references, and exploit status.

24 CVEsRSS

CVE-2026-53660High· 7.4
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and O…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-62263Critical· 9.2
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only …

MidnightOpenIdentityPlatform · OpenAMEPSS 0.55%via NVD
CVE-2026-62280Medium· 6.1
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl wi…

SunlitOpenIdentityPlatform · OpenAMEPSS 0.21%via NVD
CVE-2026-62379Critical· 9.8
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUti…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.65%via NVD
CVE-2026-47424High· 7.5
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.35%via NVD
CVE-2026-47426High· 7.6
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to …

TwilightOpenIdentityPlatform · OpenAMEPSS 0.40%via NVD
CVE-2026-48717Critical· 9.1
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization co…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-41573High· 7.1
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protectio…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.36%via NVD
CVE-2026-44202Medium· 5.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrativ…

SunlitOpenIdentityPlatform · OpenAMEPSS 0.32%via NVD
CVE-2026-44203High· 8.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.47%via NVD
CVE-2026-44793High· 7.0
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 clust…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.45%via NVD
CVE-2026-46495Critical· 9.2
6d ago

OpenDJ is an LDAPv3 compliant directory service

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authen…

MidnightOpenIdentityPlatform · OpenDJEPSS 0.73%via NVD
CVE-2026-45048High· 8.5
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries s…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.25%via NVD
CVE-2026-46619Critical· 9.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.58%via NVD
CVE-2026-46623High· 7.4
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.49%via NVD
CVE-2026-45051Critical· 9.2
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInp…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.51%via NVD
CVE-2026-45052Critical· 9.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into …

MidnightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-45794High· 7.7
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.52%via NVD
CVE-2026-46498High· 7.6
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.32%via NVD
GHSA-68r5-9hpg-7qw9Critical· 9.4
1mo ago

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-dsml-servletvia GHSA
GHSA-p279-2cqp-84jgCritical· 9.6
1mo ago

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-server-legacyvia GHSA
CVE-2026-46560High· 7.5
2mo ago

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

Twilightopenidentityplatform · org.openidentityplatform.openam:openam-radiusvia GHSA
CVE-2026-45049High· 8.3
3mo ago

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

Twilightopenidentityplatform · org.openidentityplatform.openam:openam-federationvia GHSA
CVE-2026-33439Critical· 9.8PoC
5mo ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP…

Abyssalopenidentityplatform · openamEPSS 10%via NVD
OpenIdentityPlatform vulnerabilities (CVEs) · VulnSea