Access Management Vulnerability in OpenAM Affects Push Notification Handling
CVE-2026-45794

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-45794?

Prior to version 16.1.1, OpenAM handles anonymous Push Notification SNS callbacks insecurely, allowing low-privileged users to exploit a deserialization flaw. Upon expiry of a messageId from the in-memory dispatcher, the system treats top-level blob keys as Java class names, enabling attackers to manipulate the deserialization process via JSON payloads. This can lead to arbitrary class loading, potential file system writes, and denial of service. Upgrading to version 16.1.1 mitigates these risks.

Affected Version(s)

OpenAM < 16.1.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.