Authorization Bypass Vulnerability in OpenAM by ForgeRock
CVE-2026-105120
6.9MEDIUM
What is CVE-2026-105120?
The OpenAM software from ForgeRock, prior to version 16.1.3, is susceptible to an authorization bypass vulnerability that affects the sessions REST endpoint. Specifically, realm administrators may exploit this flaw to access session information for any realm, potentially exposing usernames, universal IDs, and session handles. This situation arises when attackers wield delegated RealmAdmin privileges and use a _queryFilter to target sessions from other realms, leading to cross-tenant data access and increased security risks.
Affected Version(s)
OpenAM 0 < 16.1.3
OpenAM 0 < 16.1.3
OpenAM 16.1.3
