Improper Authorization Vulnerability in OpenAM by ForgeRock
CVE-2026-105121
6.9MEDIUM
What is CVE-2026-105121?
OpenAM prior to version 16.1.3 is impacted by an improper authorization vulnerability that permits delegated administrators to terminate user sessions in realms they do not control. This occurs due to a flaw in realm validation, where checks are only based on the requester's realm. Administrators with specific session destruction permissions can manipulate session identifiers to forcibly log users out from any realm, raising significant security concerns regarding unauthorized access and session hijacking.
Affected Version(s)
OpenAM 0 < 16.1.3
OpenAM 16.1.3
