Authorization Bypass Vulnerability in OpenAM by ForgeRock
CVE-2026-105120

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105120?

The OpenAM software from ForgeRock, prior to version 16.1.3, is susceptible to an authorization bypass vulnerability that affects the sessions REST endpoint. Specifically, realm administrators may exploit this flaw to access session information for any realm, potentially exposing usernames, universal IDs, and session handles. This situation arises when attackers wield delegated RealmAdmin privileges and use a _queryFilter to target sessions from other realms, leading to cross-tenant data access and increased security risks.

Affected Version(s)

OpenAM 0 < 16.1.3

OpenAM 0 < 16.1.3

OpenAM 16.1.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vharseko
maximthomas
tsujiguchitky
.