Access Management Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-45048

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-45048?

OpenAM, an access management solution provided by OpenIdentityPlatform, has a vulnerability in its SessionRequestHandler component. This issue arises before version 16.1.1, where the session management endpoint fails to enforce proper ownership and privilege checks. As a result, a low-privileged authenticated user can query the session information of others, allowing them to retrieve active session credentials, including those associated with more privileged accounts. This opens the door to potential session hijacking. The vulnerability is addressed in version 16.1.1, making it essential for users to upgrade to protect against unauthorized access.

Affected Version(s)

OpenAM < 16.1.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.