Access Management Vulnerability in OpenAM Affects Push Notification Handling
CVE-2026-45794
7.7HIGH
What is CVE-2026-45794?
Prior to version 16.1.1, OpenAM handles anonymous Push Notification SNS callbacks insecurely, allowing low-privileged users to exploit a deserialization flaw. Upon expiry of a messageId from the in-memory dispatcher, the system treats top-level blob keys as Java class names, enabling attackers to manipulate the deserialization process via JSON payloads. This can lead to arbitrary class loading, potential file system writes, and denial of service. Upgrading to version 16.1.1 mitigates these risks.
Affected Version(s)
OpenAM < 16.1.1
