Deserialization Vulnerability in Open Access Management Solution by OpenIdentityPlatform
CVE-2026-45051
9.2CRITICAL
What is CVE-2026-45051?
Open Access Management (OpenAM) allows for insecure deserialization of data, leading to potential exploitation. The WebAuthnAuthentication component improperly loads serialized AuthenticatorImpl object graphs from user attributes without necessary input filtering. This vulnerability can allow attackers to execute arbitrary code within the application server if specific conditions around data manipulation and user attributes are met. As such, it is crucial for users to upgrade to version 16.1.1, which addresses this issue and enhances its security posture.
Affected Version(s)
OpenAM < 16.1.1
