Deserialization Vulnerability in Open Access Management Solution by OpenIdentityPlatform
CVE-2026-45051

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-45051?

Open Access Management (OpenAM) allows for insecure deserialization of data, leading to potential exploitation. The WebAuthnAuthentication component improperly loads serialized AuthenticatorImpl object graphs from user attributes without necessary input filtering. This vulnerability can allow attackers to execute arbitrary code within the application server if specific conditions around data manipulation and user attributes are met. As such, it is crucial for users to upgrade to version 16.1.1, which addresses this issue and enhances its security posture.

Affected Version(s)

OpenAM < 16.1.1

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.