Access Management Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-44202
5.3MEDIUM
What is CVE-2026-44202?
The OpenAM access management solution suffers from a vulnerability in the /sessionservice addSessionListener operation prior to version 16.1.1. This security flaw allows authenticated users to register arbitrary notification URLs without the need for an administrative or application client token. As a result, the SessionRequestHandler transmits attacker-controlled destinations to the session listener service, potentially exposing session-related information to unauthorized external locations. This could lead to significant privacy concerns and unauthorized access to sensitive data.
Affected Version(s)
OpenAM < 16.1.1
