Access Management Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-46498
What is CVE-2026-46498?
OpenAM, an access management solution by OpenIdentityPlatform, contains a vulnerability that allows attackers to exploit OAuthTokenStore to read unverified token identifiers. This is facilitated through the shared Core Token Store (CTS) without proper OAuth-only namespace checks and by not validating critical attributes of the tokens. An attacker with the ability to input controlled JSON into the CTS can generate OAuth bearer tokens and OpenID Connect ID tokens with specific attributes. While this vulnerability does not directly create an OpenAM SSO session or provide console access, it poses significant risks to the integrity and security of the system. Users are encouraged to upgrade to version 16.1.1 to mitigate this security issue.
Affected Version(s)
OpenAM < 16.1.1
