Access Management Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-46623

7.4HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-46623?

The OAuth2 authentication module in OpenAM prior to version 16.1.1 contains a vulnerability that allows an attacker to exploit improper account updates. By changing the username to the password and reactivating disabled accounts, unauthorized users could gain access without proper authentication. This flaw arises from insufficient filtering of sensitive credentials during profile updates. Specifically, it enables local accounts to be compromised via repeated OAuth logins, where the ldapService interprets the username as the password, allowing potential account takeovers. This issue was resolved in the release of version 16.1.1.

Affected Version(s)

OpenAM < 16.1.1

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.